mirror of
https://github.com/outbackdingo/optimclaw.git
synced 2026-08-26 15:40:18 +00:00
Compare commits
43
Commits
okta-tools
...
v0.3.0
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
5e44185e48 | ||
|
|
72623c9e5b | ||
|
|
6895adbcc9 | ||
|
|
f1480f471b | ||
|
|
9db949746f | ||
|
|
61a123a746 | ||
|
|
0e981429ee | ||
|
|
1b38a64e15 | ||
|
|
2e5f8b60d5 | ||
|
|
f0a0642e7d | ||
|
|
ca8d5c6b5e | ||
|
|
9fed8453c7 | ||
|
|
eaef335db6 | ||
|
|
225af29db2 | ||
|
|
a53b2c10b5 | ||
|
|
408ae8a29a | ||
|
|
d9ff86d7e0 | ||
|
|
e843c18141 | ||
|
|
54e9206f0b | ||
|
|
5df0d13b59 | ||
|
|
bbb68f7490 | ||
|
|
b3dee13954 | ||
|
|
33ef0a6ea5 | ||
|
|
e0a43c81f9 | ||
|
|
bada79ba4a | ||
|
|
a70c89d9e3 | ||
|
|
247445f819 | ||
|
|
14254a699f | ||
|
|
2039442885 | ||
|
|
e796b838fa | ||
|
|
54ce7434fb | ||
|
|
e9e0374c85 | ||
|
|
5582a0dfbf | ||
|
|
1cf08a4b42 | ||
|
|
d55b302b39 | ||
|
|
517be42ccc | ||
|
|
09198c68ab | ||
|
|
115b7f38fe | ||
|
|
bb228f6315 | ||
|
|
45f547c711 | ||
|
|
23de75d75b | ||
|
|
ced83d5b4d | ||
|
|
202665a55c |
@@ -0,0 +1,8 @@
|
|||||||
|
target/
|
||||||
|
.git/
|
||||||
|
.env
|
||||||
|
.env.*
|
||||||
|
*.md
|
||||||
|
!CLAUDE.md
|
||||||
|
node_modules/
|
||||||
|
tools-src/
|
||||||
+3
-3
@@ -1,15 +1,15 @@
|
|||||||
# Database Configuration
|
# Database Configuration
|
||||||
DATABASE_URL=postgres://ironclaw:password@localhost:5432/ironclaw
|
DATABASE_URL=postgres://localhost/ironclaw
|
||||||
DATABASE_POOL_SIZE=10
|
DATABASE_POOL_SIZE=10
|
||||||
|
|
||||||
# LLM Provider (NEAR AI)
|
# LLM Provider (NEAR AI)
|
||||||
# NEAR AI provides a unified interface to all models with user authentication
|
# NEAR AI provides a unified interface to all models with user authentication
|
||||||
# Session token is stored in ~/.near-agent/session.json and managed automatically.
|
# Session token is stored in ~/.ironclaw/session.json and managed automatically.
|
||||||
# On first run, the agent will open a browser for OAuth authentication.
|
# On first run, the agent will open a browser for OAuth authentication.
|
||||||
NEARAI_MODEL=claude-3-5-sonnet-20241022
|
NEARAI_MODEL=claude-3-5-sonnet-20241022
|
||||||
NEARAI_BASE_URL=https://cloud-api.near.ai
|
NEARAI_BASE_URL=https://cloud-api.near.ai
|
||||||
NEARAI_AUTH_URL=https://private.near.ai
|
NEARAI_AUTH_URL=https://private.near.ai
|
||||||
# NEARAI_SESSION_PATH=~/.near-agent/session.json # optional, default shown
|
# NEARAI_SESSION_PATH=~/.ironclaw/session.json # optional, default shown
|
||||||
|
|
||||||
# Channel Configuration
|
# Channel Configuration
|
||||||
# CLI is always enabled
|
# CLI is always enabled
|
||||||
|
|||||||
@@ -0,0 +1,22 @@
|
|||||||
|
name: Code Style
|
||||||
|
on:
|
||||||
|
pull_request:
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
codestyle:
|
||||||
|
name: Code Style (fmt + clippy)
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- name: Checkout repository
|
||||||
|
uses: actions/checkout@v6
|
||||||
|
- name: Install Rust
|
||||||
|
uses: dtolnay/rust-toolchain@stable
|
||||||
|
with:
|
||||||
|
profile: minimal
|
||||||
|
components: rustfmt, clippy
|
||||||
|
- uses: Swatinem/rust-cache@v2
|
||||||
|
- name: Check formatting
|
||||||
|
run: |
|
||||||
|
cargo fmt --all -- --check
|
||||||
|
- name: Check lints (cargo clippy)
|
||||||
|
run: cargo clippy -- -D warnings
|
||||||
@@ -0,0 +1,67 @@
|
|||||||
|
name: Release-plz
|
||||||
|
|
||||||
|
on:
|
||||||
|
push:
|
||||||
|
branches:
|
||||||
|
- main
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
|
||||||
|
# Release unpublished packages.
|
||||||
|
release-plz-release:
|
||||||
|
if: ${{ github.repository_owner == 'nearai' }}
|
||||||
|
name: Release-plz release
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
permissions:
|
||||||
|
contents: write
|
||||||
|
steps:
|
||||||
|
- &checkout
|
||||||
|
name: Checkout repository
|
||||||
|
uses: actions/checkout@v6
|
||||||
|
with:
|
||||||
|
fetch-depth: 0
|
||||||
|
persist-credentials: false
|
||||||
|
- &install-rust
|
||||||
|
name: Install Rust toolchain
|
||||||
|
uses: dtolnay/rust-toolchain@stable
|
||||||
|
- uses: Swatinem/rust-cache@v2
|
||||||
|
# Generating a GitHub token, so that PRs and tags created by
|
||||||
|
# the release-plz-action can trigger actions workflows.
|
||||||
|
- name: Generate GitHub token
|
||||||
|
uses: actions/create-github-app-token@v2
|
||||||
|
id: generate-token
|
||||||
|
with:
|
||||||
|
# GitHub App ID secret name
|
||||||
|
app-id: ${{ secrets.GH_RELEASES_MANAGER_APP_ID }}
|
||||||
|
# GitHub App private key secret name
|
||||||
|
private-key: ${{ secrets.GH_RELEASES_MANAGER_APP_PRIVATE_KEY }}
|
||||||
|
- name: Run release-plz
|
||||||
|
uses: release-plz/[email protected]
|
||||||
|
with:
|
||||||
|
command: release
|
||||||
|
env:
|
||||||
|
GITHUB_TOKEN: ${{ steps.generate-token.outputs.token }}
|
||||||
|
CARGO_REGISTRY_TOKEN: ${{ secrets.CARGO_REGISTRY_TOKEN }}
|
||||||
|
|
||||||
|
# Create a PR with the new versions and changelog, preparing the next release.
|
||||||
|
release-plz-pr:
|
||||||
|
if: ${{ github.repository_owner == 'nearai' }}
|
||||||
|
name: Release-plz PR
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
permissions:
|
||||||
|
contents: write
|
||||||
|
pull-requests: write
|
||||||
|
concurrency:
|
||||||
|
group: release-plz-${{ github.ref }}
|
||||||
|
cancel-in-progress: false
|
||||||
|
steps:
|
||||||
|
- *checkout
|
||||||
|
- *install-rust
|
||||||
|
- uses: Swatinem/rust-cache@v2
|
||||||
|
- name: Run release-plz
|
||||||
|
uses: release-plz/[email protected]
|
||||||
|
with:
|
||||||
|
command: release-pr
|
||||||
|
env:
|
||||||
|
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||||
|
CARGO_REGISTRY_TOKEN: ${{ secrets.CARGO_REGISTRY_TOKEN }}
|
||||||
@@ -0,0 +1,299 @@
|
|||||||
|
# This file was autogenerated by dist: https://axodotdev.github.io/cargo-dist
|
||||||
|
#
|
||||||
|
# Copyright 2022-2024, axodotdev
|
||||||
|
# SPDX-License-Identifier: MIT or Apache-2.0
|
||||||
|
#
|
||||||
|
# CI that:
|
||||||
|
#
|
||||||
|
# * checks for a Git Tag that looks like a release
|
||||||
|
# * builds artifacts with dist (archives, installers, hashes)
|
||||||
|
# * uploads those artifacts to temporary workflow zip
|
||||||
|
# * on success, uploads the artifacts to a GitHub Release
|
||||||
|
#
|
||||||
|
# Note that the GitHub Release will be created with a generated
|
||||||
|
# title/body based on your changelogs.
|
||||||
|
|
||||||
|
name: Release
|
||||||
|
permissions:
|
||||||
|
"contents": "write"
|
||||||
|
|
||||||
|
# This task will run whenever you push a git tag that looks like a version
|
||||||
|
# like "1.0.0", "v0.1.0-prerelease.1", "my-app/0.1.0", "releases/v1.0.0", etc.
|
||||||
|
# Various formats will be parsed into a VERSION and an optional PACKAGE_NAME, where
|
||||||
|
# PACKAGE_NAME must be the name of a Cargo package in your workspace, and VERSION
|
||||||
|
# must be a Cargo-style SemVer Version (must have at least major.minor.patch).
|
||||||
|
#
|
||||||
|
# If PACKAGE_NAME is specified, then the announcement will be for that
|
||||||
|
# package (erroring out if it doesn't have the given version or isn't dist-able).
|
||||||
|
#
|
||||||
|
# If PACKAGE_NAME isn't specified, then the announcement will be for all
|
||||||
|
# (dist-able) packages in the workspace with that version (this mode is
|
||||||
|
# intended for workspaces with only one dist-able package, or with all dist-able
|
||||||
|
# packages versioned/released in lockstep).
|
||||||
|
#
|
||||||
|
# If you push multiple tags at once, separate instances of this workflow will
|
||||||
|
# spin up, creating an independent announcement for each one. However, GitHub
|
||||||
|
# will hard limit this to 3 tags per commit, as it will assume more tags is a
|
||||||
|
# mistake.
|
||||||
|
#
|
||||||
|
# If there's a prerelease-style suffix to the version, then the release(s)
|
||||||
|
# will be marked as a prerelease.
|
||||||
|
on:
|
||||||
|
push:
|
||||||
|
tags:
|
||||||
|
- '**[0-9]+.[0-9]+.[0-9]+*'
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
# Run 'dist plan' (or host) to determine what tasks we need to do
|
||||||
|
plan:
|
||||||
|
runs-on: "ubuntu-22.04"
|
||||||
|
outputs:
|
||||||
|
val: ${{ steps.plan.outputs.manifest }}
|
||||||
|
tag: ${{ !github.event.pull_request && github.ref_name || '' }}
|
||||||
|
tag-flag: ${{ !github.event.pull_request && format('--tag={0}', github.ref_name) || '' }}
|
||||||
|
publishing: ${{ !github.event.pull_request }}
|
||||||
|
env:
|
||||||
|
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||||
|
steps:
|
||||||
|
- uses: actions/checkout@v4
|
||||||
|
with:
|
||||||
|
persist-credentials: false
|
||||||
|
submodules: recursive
|
||||||
|
- name: Install dist
|
||||||
|
# we specify bash to get pipefail; it guards against the `curl` command
|
||||||
|
# failing. otherwise `sh` won't catch that `curl` returned non-0
|
||||||
|
shell: bash
|
||||||
|
run: "curl --proto '=https' --tlsv1.2 -LsSf https://github.com/axodotdev/cargo-dist/releases/download/v0.30.3/cargo-dist-installer.sh | sh"
|
||||||
|
- name: Cache dist
|
||||||
|
uses: actions/upload-artifact@v4
|
||||||
|
with:
|
||||||
|
name: cargo-dist-cache
|
||||||
|
path: ~/.cargo/bin/dist
|
||||||
|
# sure would be cool if github gave us proper conditionals...
|
||||||
|
# so here's a doubly-nested ternary-via-truthiness to try to provide the best possible
|
||||||
|
# functionality based on whether this is a pull_request, and whether it's from a fork.
|
||||||
|
# (PRs run on the *source* but secrets are usually on the *target* -- that's *good*
|
||||||
|
# but also really annoying to build CI around when it needs secrets to work right.)
|
||||||
|
- id: plan
|
||||||
|
run: |
|
||||||
|
dist ${{ (!github.event.pull_request && format('host --steps=create --tag={0}', github.ref_name)) || 'plan' }} --output-format=json > plan-dist-manifest.json
|
||||||
|
echo "dist ran successfully"
|
||||||
|
cat plan-dist-manifest.json
|
||||||
|
echo "manifest=$(jq -c "." plan-dist-manifest.json)" >> "$GITHUB_OUTPUT"
|
||||||
|
- name: "Upload dist-manifest.json"
|
||||||
|
uses: actions/upload-artifact@v4
|
||||||
|
with:
|
||||||
|
name: artifacts-plan-dist-manifest
|
||||||
|
path: plan-dist-manifest.json
|
||||||
|
|
||||||
|
# Build and packages all the platform-specific things
|
||||||
|
build-local-artifacts:
|
||||||
|
name: build-local-artifacts (${{ join(matrix.targets, ', ') }})
|
||||||
|
# Let the initial task tell us to not run (currently very blunt)
|
||||||
|
needs:
|
||||||
|
- plan
|
||||||
|
if: ${{ fromJson(needs.plan.outputs.val).ci.github.artifacts_matrix.include != null && (needs.plan.outputs.publishing == 'true' || fromJson(needs.plan.outputs.val).ci.github.pr_run_mode == 'upload') }}
|
||||||
|
strategy:
|
||||||
|
fail-fast: false
|
||||||
|
# Target platforms/runners are computed by dist in create-release.
|
||||||
|
# Each member of the matrix has the following arguments:
|
||||||
|
#
|
||||||
|
# - runner: the github runner
|
||||||
|
# - dist-args: cli flags to pass to dist
|
||||||
|
# - install-dist: expression to run to install dist on the runner
|
||||||
|
#
|
||||||
|
# Typically there will be:
|
||||||
|
# - 1 "global" task that builds universal installers
|
||||||
|
# - N "local" tasks that build each platform's binaries and platform-specific installers
|
||||||
|
matrix: ${{ fromJson(needs.plan.outputs.val).ci.github.artifacts_matrix }}
|
||||||
|
runs-on: ${{ matrix.runner }}
|
||||||
|
container: ${{ matrix.container && matrix.container.image || null }}
|
||||||
|
env:
|
||||||
|
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||||
|
BUILD_MANIFEST_NAME: target/distrib/${{ join(matrix.targets, '-') }}-dist-manifest.json
|
||||||
|
steps:
|
||||||
|
- name: enable windows longpaths
|
||||||
|
run: |
|
||||||
|
git config --global core.longpaths true
|
||||||
|
- uses: actions/checkout@v4
|
||||||
|
with:
|
||||||
|
persist-credentials: false
|
||||||
|
submodules: recursive
|
||||||
|
- name: Install Rust non-interactively if not already installed
|
||||||
|
if: ${{ matrix.container }}
|
||||||
|
run: |
|
||||||
|
if ! command -v cargo > /dev/null 2>&1; then
|
||||||
|
curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh -s -- -y
|
||||||
|
echo "$HOME/.cargo/bin" >> $GITHUB_PATH
|
||||||
|
fi
|
||||||
|
- uses: swatinem/rust-cache@v2
|
||||||
|
with:
|
||||||
|
key: ${{ join(matrix.targets, '-') }}
|
||||||
|
cache-provider: ${{ matrix.cache_provider }}
|
||||||
|
- name: Install dist
|
||||||
|
run: ${{ matrix.install_dist.run }}
|
||||||
|
# Get the dist-manifest
|
||||||
|
- name: Fetch local artifacts
|
||||||
|
uses: actions/download-artifact@v4
|
||||||
|
with:
|
||||||
|
pattern: artifacts-*
|
||||||
|
path: target/distrib/
|
||||||
|
merge-multiple: true
|
||||||
|
- name: Install dependencies
|
||||||
|
run: |
|
||||||
|
${{ matrix.packages_install }}
|
||||||
|
- name: Build artifacts
|
||||||
|
run: |
|
||||||
|
# Actually do builds and make zips and whatnot
|
||||||
|
dist build ${{ needs.plan.outputs.tag-flag }} --print=linkage --output-format=json ${{ matrix.dist_args }} > dist-manifest.json
|
||||||
|
echo "dist ran successfully"
|
||||||
|
- id: cargo-dist
|
||||||
|
name: Post-build
|
||||||
|
# We force bash here just because github makes it really hard to get values up
|
||||||
|
# to "real" actions without writing to env-vars, and writing to env-vars has
|
||||||
|
# inconsistent syntax between shell and powershell.
|
||||||
|
shell: bash
|
||||||
|
run: |
|
||||||
|
# Parse out what we just built and upload it to scratch storage
|
||||||
|
echo "paths<<EOF" >> "$GITHUB_OUTPUT"
|
||||||
|
dist print-upload-files-from-manifest --manifest dist-manifest.json >> "$GITHUB_OUTPUT"
|
||||||
|
echo "EOF" >> "$GITHUB_OUTPUT"
|
||||||
|
|
||||||
|
cp dist-manifest.json "$BUILD_MANIFEST_NAME"
|
||||||
|
- name: "Upload artifacts"
|
||||||
|
uses: actions/upload-artifact@v4
|
||||||
|
with:
|
||||||
|
name: artifacts-build-local-${{ join(matrix.targets, '_') }}
|
||||||
|
path: |
|
||||||
|
${{ steps.cargo-dist.outputs.paths }}
|
||||||
|
${{ env.BUILD_MANIFEST_NAME }}
|
||||||
|
|
||||||
|
# Build and package all the platform-agnostic(ish) things
|
||||||
|
build-global-artifacts:
|
||||||
|
needs:
|
||||||
|
- plan
|
||||||
|
- build-local-artifacts
|
||||||
|
runs-on: "ubuntu-22.04"
|
||||||
|
env:
|
||||||
|
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||||
|
BUILD_MANIFEST_NAME: target/distrib/global-dist-manifest.json
|
||||||
|
steps:
|
||||||
|
- uses: actions/checkout@v4
|
||||||
|
with:
|
||||||
|
persist-credentials: false
|
||||||
|
submodules: recursive
|
||||||
|
- name: Install cached dist
|
||||||
|
uses: actions/download-artifact@v4
|
||||||
|
with:
|
||||||
|
name: cargo-dist-cache
|
||||||
|
path: ~/.cargo/bin/
|
||||||
|
- run: chmod +x ~/.cargo/bin/dist
|
||||||
|
# Get all the local artifacts for the global tasks to use (for e.g. checksums)
|
||||||
|
- name: Fetch local artifacts
|
||||||
|
uses: actions/download-artifact@v4
|
||||||
|
with:
|
||||||
|
pattern: artifacts-*
|
||||||
|
path: target/distrib/
|
||||||
|
merge-multiple: true
|
||||||
|
- id: cargo-dist
|
||||||
|
shell: bash
|
||||||
|
run: |
|
||||||
|
dist build ${{ needs.plan.outputs.tag-flag }} --output-format=json "--artifacts=global" > dist-manifest.json
|
||||||
|
echo "dist ran successfully"
|
||||||
|
|
||||||
|
# Parse out what we just built and upload it to scratch storage
|
||||||
|
echo "paths<<EOF" >> "$GITHUB_OUTPUT"
|
||||||
|
jq --raw-output ".upload_files[]" dist-manifest.json >> "$GITHUB_OUTPUT"
|
||||||
|
echo "EOF" >> "$GITHUB_OUTPUT"
|
||||||
|
|
||||||
|
cp dist-manifest.json "$BUILD_MANIFEST_NAME"
|
||||||
|
- name: "Upload artifacts"
|
||||||
|
uses: actions/upload-artifact@v4
|
||||||
|
with:
|
||||||
|
name: artifacts-build-global
|
||||||
|
path: |
|
||||||
|
${{ steps.cargo-dist.outputs.paths }}
|
||||||
|
${{ env.BUILD_MANIFEST_NAME }}
|
||||||
|
# Determines if we should publish/announce
|
||||||
|
host:
|
||||||
|
needs:
|
||||||
|
- plan
|
||||||
|
- build-local-artifacts
|
||||||
|
- build-global-artifacts
|
||||||
|
# Only run if we're "publishing", and only if plan, local and global didn't fail (skipped is fine)
|
||||||
|
if: ${{ always() && needs.plan.result == 'success' && needs.plan.outputs.publishing == 'true' && (needs.build-global-artifacts.result == 'skipped' || needs.build-global-artifacts.result == 'success') && (needs.build-local-artifacts.result == 'skipped' || needs.build-local-artifacts.result == 'success') }}
|
||||||
|
env:
|
||||||
|
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||||
|
runs-on: "ubuntu-22.04"
|
||||||
|
outputs:
|
||||||
|
val: ${{ steps.host.outputs.manifest }}
|
||||||
|
steps:
|
||||||
|
- uses: actions/checkout@v4
|
||||||
|
with:
|
||||||
|
persist-credentials: false
|
||||||
|
submodules: recursive
|
||||||
|
- name: Install cached dist
|
||||||
|
uses: actions/download-artifact@v4
|
||||||
|
with:
|
||||||
|
name: cargo-dist-cache
|
||||||
|
path: ~/.cargo/bin/
|
||||||
|
- run: chmod +x ~/.cargo/bin/dist
|
||||||
|
# Fetch artifacts from scratch-storage
|
||||||
|
- name: Fetch artifacts
|
||||||
|
uses: actions/download-artifact@v4
|
||||||
|
with:
|
||||||
|
pattern: artifacts-*
|
||||||
|
path: target/distrib/
|
||||||
|
merge-multiple: true
|
||||||
|
- id: host
|
||||||
|
shell: bash
|
||||||
|
run: |
|
||||||
|
dist host ${{ needs.plan.outputs.tag-flag }} --steps=upload --steps=release --output-format=json > dist-manifest.json
|
||||||
|
echo "artifacts uploaded and released successfully"
|
||||||
|
cat dist-manifest.json
|
||||||
|
echo "manifest=$(jq -c "." dist-manifest.json)" >> "$GITHUB_OUTPUT"
|
||||||
|
- name: "Upload dist-manifest.json"
|
||||||
|
uses: actions/upload-artifact@v4
|
||||||
|
with:
|
||||||
|
# Overwrite the previous copy
|
||||||
|
name: artifacts-dist-manifest
|
||||||
|
path: dist-manifest.json
|
||||||
|
# Create a GitHub Release while uploading all files to it
|
||||||
|
- name: "Download GitHub Artifacts"
|
||||||
|
uses: actions/download-artifact@v4
|
||||||
|
with:
|
||||||
|
pattern: artifacts-*
|
||||||
|
path: artifacts
|
||||||
|
merge-multiple: true
|
||||||
|
- name: Cleanup
|
||||||
|
run: |
|
||||||
|
# Remove the granular manifests
|
||||||
|
rm -f artifacts/*-dist-manifest.json
|
||||||
|
- name: Create GitHub Release
|
||||||
|
env:
|
||||||
|
PRERELEASE_FLAG: "${{ fromJson(steps.host.outputs.manifest).announcement_is_prerelease && '--prerelease' || '' }}"
|
||||||
|
ANNOUNCEMENT_TITLE: "${{ fromJson(steps.host.outputs.manifest).announcement_title }}"
|
||||||
|
ANNOUNCEMENT_BODY: "${{ fromJson(steps.host.outputs.manifest).announcement_github_body }}"
|
||||||
|
RELEASE_COMMIT: "${{ github.sha }}"
|
||||||
|
run: |
|
||||||
|
# Write and read notes from a file to avoid quoting breaking things
|
||||||
|
echo "$ANNOUNCEMENT_BODY" > $RUNNER_TEMP/notes.txt
|
||||||
|
|
||||||
|
gh release create "${{ needs.plan.outputs.tag }}" --target "$RELEASE_COMMIT" $PRERELEASE_FLAG --title "$ANNOUNCEMENT_TITLE" --notes-file "$RUNNER_TEMP/notes.txt" artifacts/*
|
||||||
|
|
||||||
|
announce:
|
||||||
|
needs:
|
||||||
|
- plan
|
||||||
|
- host
|
||||||
|
# use "always() && ..." to allow us to wait for all publish jobs while
|
||||||
|
# still allowing individual publish jobs to skip themselves (for prereleases).
|
||||||
|
# "host" however must run to completion, no skipping allowed!
|
||||||
|
if: ${{ always() && needs.host.result == 'success' }}
|
||||||
|
runs-on: "ubuntu-22.04"
|
||||||
|
env:
|
||||||
|
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||||
|
steps:
|
||||||
|
- uses: actions/checkout@v4
|
||||||
|
with:
|
||||||
|
persist-credentials: false
|
||||||
|
submodules: recursive
|
||||||
@@ -0,0 +1,21 @@
|
|||||||
|
name: Run Tests
|
||||||
|
on:
|
||||||
|
pull_request:
|
||||||
|
push:
|
||||||
|
branches:
|
||||||
|
- main
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
tests:
|
||||||
|
name: Run Tests
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- name: Checkout repository
|
||||||
|
uses: actions/checkout@v6
|
||||||
|
- name: Install Rust
|
||||||
|
uses: dtolnay/rust-toolchain@stable
|
||||||
|
with:
|
||||||
|
profile: minimal
|
||||||
|
- uses: Swatinem/rust-cache@v2
|
||||||
|
- name: Run Tests
|
||||||
|
run: cargo test --all-features -- --nocapture
|
||||||
@@ -1,6 +1,11 @@
|
|||||||
|
|
||||||
.env
|
.env
|
||||||
.env.local
|
.env.local
|
||||||
|
.env.*
|
||||||
|
!.env.example
|
||||||
|
|
||||||
target/
|
target/
|
||||||
|
|
||||||
|
# WASM build artifacts (loaded from disk, not bundled)
|
||||||
|
*.wasm
|
||||||
|
|
||||||
|
|||||||
+153
@@ -0,0 +1,153 @@
|
|||||||
|
# Changelog
|
||||||
|
|
||||||
|
All notable changes to this project will be documented in this file.
|
||||||
|
|
||||||
|
The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/),
|
||||||
|
and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html).
|
||||||
|
|
||||||
|
## [Unreleased]
|
||||||
|
|
||||||
|
## [0.3.0](https://github.com/nearai/ironclaw/compare/v0.2.0...v0.3.0) - 2026-02-17
|
||||||
|
|
||||||
|
### Added
|
||||||
|
|
||||||
|
- direct api key and cheap model ([#116](https://github.com/nearai/ironclaw/pull/116))
|
||||||
|
|
||||||
|
## [0.2.0](https://github.com/nearai/ironclaw/compare/v0.1.3...v0.2.0) - 2026-02-16
|
||||||
|
|
||||||
|
### Added
|
||||||
|
|
||||||
|
- mark Ollama + OpenAI-compatible as implemented ([#102](https://github.com/nearai/ironclaw/pull/102))
|
||||||
|
- multi-provider inference + libSQL onboarding selection ([#92](https://github.com/nearai/ironclaw/pull/92))
|
||||||
|
- add multi-provider LLM failover with retry backoff ([#28](https://github.com/nearai/ironclaw/pull/28))
|
||||||
|
- add libSQL/Turso embedded database backend ([#47](https://github.com/nearai/ironclaw/pull/47))
|
||||||
|
- Move debug log truncation from agent loop to REPL channel ([#65](https://github.com/nearai/ironclaw/pull/65))
|
||||||
|
|
||||||
|
### Fixed
|
||||||
|
|
||||||
|
- shell destructive-command check bypassed by Value::Object arguments ([#72](https://github.com/nearai/ironclaw/pull/72))
|
||||||
|
- propagate real tool_call_id instead of hardcoded placeholder ([#73](https://github.com/nearai/ironclaw/pull/73))
|
||||||
|
- Fix wasm tool schemas and runtime ([#42](https://github.com/nearai/ironclaw/pull/42))
|
||||||
|
- flatten tool messages for NEAR AI cloud-api compatibility ([#41](https://github.com/nearai/ironclaw/pull/41))
|
||||||
|
- security hardening across all layers ([#35](https://github.com/nearai/ironclaw/pull/35))
|
||||||
|
|
||||||
|
### Other
|
||||||
|
|
||||||
|
- Explicitly enable cargo-dist caching for binary artifacts building
|
||||||
|
- Skip building binary artifacts on every PR
|
||||||
|
- add module specification rules to CLAUDE.md
|
||||||
|
- add setup/onboarding specification (src/setup/README.md)
|
||||||
|
- deduplicate tool code and remove dead stubs ([#98](https://github.com/nearai/ironclaw/pull/98))
|
||||||
|
- Reformat architecture diagram in README ([#64](https://github.com/nearai/ironclaw/pull/64))
|
||||||
|
- Add review discipline guidelines to CLAUDE.md ([#68](https://github.com/nearai/ironclaw/pull/68))
|
||||||
|
- Bump MSRV to 1.92, add GCP deployment files ([#40](https://github.com/nearai/ironclaw/pull/40))
|
||||||
|
- Add OpenAI-compatible HTTP API (/v1/chat/completions, /v1/models) ([#31](https://github.com/nearai/ironclaw/pull/31))
|
||||||
|
|
||||||
|
## [0.1.3](https://github.com/nearai/ironclaw/compare/v0.1.2...v0.1.3) - 2026-02-12
|
||||||
|
|
||||||
|
### Other
|
||||||
|
|
||||||
|
- Enabled builds caching during CI/CD
|
||||||
|
- Disabled npm publishing as the name is already taken
|
||||||
|
|
||||||
|
## [0.1.2](https://github.com/nearai/ironclaw/compare/v0.1.1...v0.1.2) - 2026-02-12
|
||||||
|
|
||||||
|
### Other
|
||||||
|
|
||||||
|
- Added Installation instructions for the pre-built binaries
|
||||||
|
- Disabled Windows ARM64 builds as auto-updater [provided by cargo-dist] does not support this platform yet and it is not a common platform for us to support
|
||||||
|
|
||||||
|
## [0.1.1](https://github.com/nearai/ironclaw/compare/v0.1.0...v0.1.1) - 2026-02-12
|
||||||
|
|
||||||
|
### Other
|
||||||
|
|
||||||
|
- Renamed the secrets in release-plz.yml to match the configuration
|
||||||
|
- Make sure that the binaries release CD it kicking in after release-plz
|
||||||
|
|
||||||
|
## [0.1.0](https://github.com/nearai/ironclaw/releases/tag/v0.1.0) - 2026-02-12
|
||||||
|
|
||||||
|
### Added
|
||||||
|
|
||||||
|
- Add multi-provider LLM support via rig-core adapter ([#36](https://github.com/nearai/ironclaw/pull/36))
|
||||||
|
- Sandbox jobs ([#4](https://github.com/nearai/ironclaw/pull/4))
|
||||||
|
- Add Google Suite & Telegram WASM tools ([#9](https://github.com/nearai/ironclaw/pull/9))
|
||||||
|
- Improve CLI ([#5](https://github.com/nearai/ironclaw/pull/5))
|
||||||
|
|
||||||
|
### Fixed
|
||||||
|
|
||||||
|
- resolve runtime panic in Linux keychain integration ([#32](https://github.com/nearai/ironclaw/pull/32))
|
||||||
|
|
||||||
|
### Other
|
||||||
|
|
||||||
|
- Skip release-plz on forks
|
||||||
|
- Upgraded release-plz CD pipeline
|
||||||
|
- Added CI/CD and release pipelines ([#45](https://github.com/nearai/ironclaw/pull/45))
|
||||||
|
- DM pairing + Telegram channel improvements ([#17](https://github.com/nearai/ironclaw/pull/17))
|
||||||
|
- Fixes build, adds missing sse event and correct command ([#11](https://github.com/nearai/ironclaw/pull/11))
|
||||||
|
- Codex/feature parity pr hook ([#6](https://github.com/nearai/ironclaw/pull/6))
|
||||||
|
- Add WebSocket gateway and control plane ([#8](https://github.com/nearai/ironclaw/pull/8))
|
||||||
|
- select bundled Telegram channel and auto-install ([#3](https://github.com/nearai/ironclaw/pull/3))
|
||||||
|
- Adding skills for reusable work
|
||||||
|
- Fix MCP tool calls, approval loop, shutdown, and improve web UI
|
||||||
|
- Add auth mode, fix MCP token handling, and parallelize startup loading
|
||||||
|
- Merge remote-tracking branch 'origin/main' into ui
|
||||||
|
- Adding web UI
|
||||||
|
- Rename `setup` CLI command to `onboard` for compatibility
|
||||||
|
- Add in-chat extension discovery, auth, and activation system
|
||||||
|
- Add Telegram typing indicator via WIT on-status callback
|
||||||
|
- Add proactivity features: memory CLI, session pruning, self-repair notifications, slash commands, status diagnostics, context warnings
|
||||||
|
- Add hosted MCP server support with OAuth 2.1 and token refresh
|
||||||
|
- Add interactive setup wizard and persistent settings
|
||||||
|
- Rebrand to IronClaw with security-first mission
|
||||||
|
- Fix build_software tool stuck in planning mode loop
|
||||||
|
- Enable sandbox by default
|
||||||
|
- Fix Telegram Markdown formatting and clarify tool/memory distinctions
|
||||||
|
- Simplify Telegram channel config with host-injected tunnel/webhook settings
|
||||||
|
- Apply Telegram channel learnings to WhatsApp implementation
|
||||||
|
- Merge remote-tracking branch 'origin/main'
|
||||||
|
- Docker file for sandbox
|
||||||
|
- Replace hardcoded intent patterns with job tools
|
||||||
|
- Fix router test to match intentional job creation patterns
|
||||||
|
- Add Docker execution sandbox for secure shell command isolation
|
||||||
|
- Move setup wizard credentials to database storage
|
||||||
|
- Add interactive setup wizard for first-run configuration
|
||||||
|
- Add Telegram Bot API channel as WASM module
|
||||||
|
- Add OpenClaw feature parity tracking matrix
|
||||||
|
- Add Chat Completions API support and expand REPL debugging
|
||||||
|
- Implementing channels to be handled in wasm
|
||||||
|
- Support non interactive mode and model selection
|
||||||
|
- Implement tool approval, fix tool definition refresh, and wire embeddings
|
||||||
|
- Tool use
|
||||||
|
- Wiring more
|
||||||
|
- Add heartbeat integration, planning phase, and auto-repair
|
||||||
|
- Login flow
|
||||||
|
- Extend support for session management
|
||||||
|
- Adding builder capability
|
||||||
|
- Load tools at launch
|
||||||
|
- Fix multiline message rendering in TUI
|
||||||
|
- Parse NEAR AI alternative response format with output field
|
||||||
|
- Handle NEAR AI plain text responses
|
||||||
|
- Disable mouse capture to allow text selection in TUI
|
||||||
|
- Add verbose logging to debug empty NEAR AI responses
|
||||||
|
- Improve NEAR AI response parsing for varying response formats
|
||||||
|
- Show status/thinking messages in chat window, debug empty responses
|
||||||
|
- Add timeout and logging to NEAR AI provider
|
||||||
|
- Add status updates to show agent thinking/processing state
|
||||||
|
- Add CLI subcommands for WASM tool management
|
||||||
|
- Fix TUI shutdown: send /shutdown message and handle in agent loop
|
||||||
|
- Remove SimpleCliChannel, add Ctrl+D twice quit, redirect logs to TUI
|
||||||
|
- Fix TuiChannel integration and enable in main.rs
|
||||||
|
- Integrate Codex patterns: task scheduler, TUI, sessions, compaction
|
||||||
|
- Adding LICENSE
|
||||||
|
- Add README with IronClaw branding
|
||||||
|
- Add WASM sandbox secure API extension
|
||||||
|
- Wire database Store into agent loop
|
||||||
|
- Implementing WASM runtime
|
||||||
|
- Add workspace integration tests
|
||||||
|
- Compact memory_tree output format
|
||||||
|
- Replace memory_list with memory_tree tool
|
||||||
|
- Simplify workspace to path-based storage, remove legacy code
|
||||||
|
- Add NEAR AI chat-api as default LLM provider
|
||||||
|
- Add CLAUDE.md project documentation
|
||||||
|
- Add workspace and memory system (OpenClaw-inspired)
|
||||||
|
- Initial implementation of the agent framework
|
||||||
@@ -11,8 +11,13 @@
|
|||||||
- **Always available** - Multi-channel access with proactive background execution
|
- **Always available** - Multi-channel access with proactive background execution
|
||||||
|
|
||||||
### Features
|
### Features
|
||||||
- **Multi-channel input**: TUI (Ratatui), HTTP webhooks, Telegram, WhatsApp, Slack (WASM channels)
|
- **Multi-channel input**: TUI (Ratatui), HTTP webhooks, WASM channels (Telegram, Slack), web gateway
|
||||||
- **Parallel job execution** with state machine and self-repair for stuck jobs
|
- **Parallel job execution** with state machine and self-repair for stuck jobs
|
||||||
|
- **Sandbox execution**: Docker container isolation with orchestrator/worker pattern
|
||||||
|
- **Claude Code mode**: Delegate jobs to Claude CLI inside containers
|
||||||
|
- **Routines**: Scheduled (cron) and reactive (event, webhook) task execution
|
||||||
|
- **Web gateway**: Browser UI with SSE/WebSocket real-time streaming
|
||||||
|
- **Extension management**: Install, auth, activate MCP/WASM extensions
|
||||||
- **Extensible tools**: Built-in tools, WASM sandbox, MCP client, dynamic builder
|
- **Extensible tools**: Built-in tools, WASM sandbox, MCP client, dynamic builder
|
||||||
- **Persistent memory**: Workspace with hybrid search (FTS + vector via RRF)
|
- **Persistent memory**: Workspace with hybrid search (FTS + vector via RRF)
|
||||||
- **Prompt injection defense**: Sanitizer, validator, policy rules, leak detection
|
- **Prompt injection defense**: Sanitizer, validator, policy rules, leak detection
|
||||||
@@ -59,7 +64,9 @@ src/
|
|||||||
│ ├── context_monitor.rs # Memory pressure detection
|
│ ├── context_monitor.rs # Memory pressure detection
|
||||||
│ ├── undo.rs # Turn-based undo/redo with checkpoints
|
│ ├── undo.rs # Turn-based undo/redo with checkpoints
|
||||||
│ ├── submission.rs # Submission parsing (undo, redo, compact, clear, etc.)
|
│ ├── submission.rs # Submission parsing (undo, redo, compact, clear, etc.)
|
||||||
│ └── task.rs # Sub-task execution framework
|
│ ├── task.rs # Sub-task execution framework
|
||||||
|
│ ├── routine.rs # Routine types (Trigger, Action, Guardrails)
|
||||||
|
│ └── routine_engine.rs # Routine execution (cron ticker, event matcher)
|
||||||
│
|
│
|
||||||
├── channels/ # Multi-channel input
|
├── channels/ # Multi-channel input
|
||||||
│ ├── channel.rs # Channel trait, IncomingMessage, OutgoingResponse
|
│ ├── channel.rs # Channel trait, IncomingMessage, OutgoingResponse
|
||||||
@@ -72,8 +79,33 @@ src/
|
|||||||
│ │ ├── overlay.rs # Approval overlays
|
│ │ ├── overlay.rs # Approval overlays
|
||||||
│ │ └── composer.rs # Message composition
|
│ │ └── composer.rs # Message composition
|
||||||
│ ├── http.rs # HTTP webhook (axum) with secret validation
|
│ ├── http.rs # HTTP webhook (axum) with secret validation
|
||||||
│ ├── slack.rs # Stub
|
│ ├── repl.rs # Simple REPL (for testing)
|
||||||
│ └── telegram.rs # Stub
|
│ ├── web/ # Web gateway (browser UI)
|
||||||
|
│ │ ├── mod.rs # Gateway builder, startup
|
||||||
|
│ │ ├── server.rs # Axum router, 40+ API endpoints
|
||||||
|
│ │ ├── sse.rs # SSE broadcast manager
|
||||||
|
│ │ ├── ws.rs # WebSocket gateway + connection tracking
|
||||||
|
│ │ ├── types.rs # Request/response types, SseEvent enum
|
||||||
|
│ │ ├── auth.rs # Bearer token auth middleware
|
||||||
|
│ │ ├── log_layer.rs # Tracing layer for log streaming
|
||||||
|
│ │ └── static/ # HTML, CSS, JS (single-page app)
|
||||||
|
│ └── wasm/ # WASM channel runtime
|
||||||
|
│ ├── mod.rs
|
||||||
|
│ ├── bundled.rs # Bundled channel discovery
|
||||||
|
│ └── wrapper.rs # Channel trait wrapper for WASM modules
|
||||||
|
│
|
||||||
|
├── orchestrator/ # Internal HTTP API for sandbox containers
|
||||||
|
│ ├── mod.rs
|
||||||
|
│ ├── api.rs # Axum endpoints (LLM proxy, events, prompts)
|
||||||
|
│ ├── auth.rs # Per-job bearer token store
|
||||||
|
│ └── job_manager.rs # Container lifecycle (create, stop, cleanup)
|
||||||
|
│
|
||||||
|
├── worker/ # Runs inside Docker containers
|
||||||
|
│ ├── mod.rs
|
||||||
|
│ ├── runtime.rs # Worker execution loop (tool calls, LLM)
|
||||||
|
│ ├── claude_bridge.rs # Claude Code bridge (spawns claude CLI)
|
||||||
|
│ ├── api.rs # HTTP client to orchestrator
|
||||||
|
│ └── proxy_llm.rs # LlmProvider that proxies through orchestrator
|
||||||
│
|
│
|
||||||
├── safety/ # Prompt injection defense
|
├── safety/ # Prompt injection defense
|
||||||
│ ├── sanitizer.rs # Pattern detection, content escaping
|
│ ├── sanitizer.rs # Pattern detection, content escaping
|
||||||
@@ -96,6 +128,9 @@ src/
|
|||||||
│ │ ├── file.rs # ReadFile, WriteFile, ListDir, ApplyPatch
|
│ │ ├── file.rs # ReadFile, WriteFile, ListDir, ApplyPatch
|
||||||
│ │ ├── shell.rs # Shell command execution
|
│ │ ├── shell.rs # Shell command execution
|
||||||
│ │ ├── memory.rs # Memory tools (search, write, read, tree)
|
│ │ ├── memory.rs # Memory tools (search, write, read, tree)
|
||||||
|
│ │ ├── job.rs # CreateJob, ListJobs, JobStatus, CancelJob
|
||||||
|
│ │ ├── routine.rs # routine_create/list/update/delete/history
|
||||||
|
│ │ ├── extension_tools.rs # Extension install/auth/activate/remove
|
||||||
│ │ └── marketplace.rs, ecommerce.rs, taskrabbit.rs, restaurant.rs (stubs)
|
│ │ └── marketplace.rs, ecommerce.rs, taskrabbit.rs, restaurant.rs (stubs)
|
||||||
│ ├── builder/ # Dynamic tool building
|
│ ├── builder/ # Dynamic tool building
|
||||||
│ │ ├── core.rs # BuildRequirement, SoftwareType, Language
|
│ │ ├── core.rs # BuildRequirement, SoftwareType, Language
|
||||||
@@ -116,6 +151,12 @@ src/
|
|||||||
│ ├── rate_limiter.rs # Per-tool rate limiting
|
│ ├── rate_limiter.rs # Per-tool rate limiting
|
||||||
│ └── storage.rs # Linear memory persistence
|
│ └── storage.rs # Linear memory persistence
|
||||||
│
|
│
|
||||||
|
├── db/ # Database abstraction layer
|
||||||
|
│ ├── mod.rs # Database trait (~60 async methods)
|
||||||
|
│ ├── postgres.rs # PostgreSQL backend (delegates to Store + Repository)
|
||||||
|
│ ├── libsql_backend.rs # libSQL/Turso backend (embedded SQLite)
|
||||||
|
│ └── libsql_migrations.rs # SQLite-dialect schema (idempotent)
|
||||||
|
│
|
||||||
├── workspace/ # Persistent memory system (OpenClaw-inspired)
|
├── workspace/ # Persistent memory system (OpenClaw-inspired)
|
||||||
│ ├── mod.rs # Workspace struct, memory operations
|
│ ├── mod.rs # Workspace struct, memory operations
|
||||||
│ ├── document.rs # MemoryDocument, MemoryChunk, WorkspaceEntry
|
│ ├── document.rs # MemoryDocument, MemoryChunk, WorkspaceEntry
|
||||||
@@ -157,8 +198,9 @@ When designing new features or systems, always prefer generic/extensible archite
|
|||||||
|
|
||||||
### Error Handling
|
### Error Handling
|
||||||
- Use `thiserror` for error types in `error.rs`
|
- Use `thiserror` for error types in `error.rs`
|
||||||
- Never use `.unwrap()` in production code (tests are fine)
|
- Never use `.unwrap()` or `.expect()` in production code (tests are fine)
|
||||||
- Map errors with context: `.map_err(|e| SomeError::Variant { reason: e.to_string() })?`
|
- Map errors with context: `.map_err(|e| SomeError::Variant { reason: e.to_string() })?`
|
||||||
|
- Before committing, grep for `.unwrap()` and `.expect(` in changed files to catch violations mechanically
|
||||||
|
|
||||||
### Async
|
### Async
|
||||||
- All I/O is async with tokio
|
- All I/O is async with tokio
|
||||||
@@ -166,6 +208,7 @@ When designing new features or systems, always prefer generic/extensible archite
|
|||||||
- Use `RwLock` for concurrent read/write access
|
- Use `RwLock` for concurrent read/write access
|
||||||
|
|
||||||
### Traits for Extensibility
|
### Traits for Extensibility
|
||||||
|
- `Database` - Add new database backends (must implement all ~60 methods)
|
||||||
- `Channel` - Add new input sources
|
- `Channel` - Add new input sources
|
||||||
- `Tool` - Add new capabilities
|
- `Tool` - Add new capabilities
|
||||||
- `LlmProvider` - Add new LLM backends
|
- `LlmProvider` - Add new LLM backends
|
||||||
@@ -213,7 +256,12 @@ Pending -> InProgress -> Completed -> Submitted -> Accepted
|
|||||||
|
|
||||||
Environment variables (see `.env.example`):
|
Environment variables (see `.env.example`):
|
||||||
```bash
|
```bash
|
||||||
|
# Database backend (default: postgres)
|
||||||
|
DATABASE_BACKEND=postgres # or "libsql" / "turso"
|
||||||
DATABASE_URL=postgres://user:pass@localhost/ironclaw
|
DATABASE_URL=postgres://user:pass@localhost/ironclaw
|
||||||
|
LIBSQL_PATH=~/.ironclaw/ironclaw.db # libSQL local path (default)
|
||||||
|
# LIBSQL_URL=libsql://xxx.turso.io # Turso cloud (optional)
|
||||||
|
# LIBSQL_AUTH_TOKEN=xxx # Required with LIBSQL_URL
|
||||||
|
|
||||||
# NEAR AI (required)
|
# NEAR AI (required)
|
||||||
NEARAI_SESSION_TOKEN=sess_...
|
NEARAI_SESSION_TOKEN=sess_...
|
||||||
@@ -236,6 +284,30 @@ HEARTBEAT_ENABLED=true
|
|||||||
HEARTBEAT_INTERVAL_SECS=1800 # 30 minutes
|
HEARTBEAT_INTERVAL_SECS=1800 # 30 minutes
|
||||||
HEARTBEAT_NOTIFY_CHANNEL=tui
|
HEARTBEAT_NOTIFY_CHANNEL=tui
|
||||||
HEARTBEAT_NOTIFY_USER=default
|
HEARTBEAT_NOTIFY_USER=default
|
||||||
|
|
||||||
|
# Web gateway
|
||||||
|
GATEWAY_ENABLED=true
|
||||||
|
GATEWAY_HOST=127.0.0.1
|
||||||
|
GATEWAY_PORT=3001
|
||||||
|
GATEWAY_AUTH_TOKEN=changeme # Required for API access
|
||||||
|
GATEWAY_USER_ID=default
|
||||||
|
|
||||||
|
# Docker sandbox
|
||||||
|
SANDBOX_ENABLED=true
|
||||||
|
SANDBOX_IMAGE=ironclaw-worker:latest
|
||||||
|
SANDBOX_MEMORY_LIMIT_MB=512
|
||||||
|
SANDBOX_TIMEOUT_SECS=1800
|
||||||
|
|
||||||
|
# Claude Code mode (runs inside sandbox containers)
|
||||||
|
CLAUDE_CODE_ENABLED=false
|
||||||
|
CLAUDE_CODE_MODEL=claude-sonnet-4-20250514
|
||||||
|
CLAUDE_CODE_MAX_TURNS=50
|
||||||
|
CLAUDE_CODE_CONFIG_DIR=/home/worker/.claude
|
||||||
|
|
||||||
|
# Routines (scheduled/reactive execution)
|
||||||
|
ROUTINES_ENABLED=true
|
||||||
|
ROUTINES_CRON_INTERVAL=60 # Tick interval in seconds
|
||||||
|
ROUTINES_MAX_CONCURRENT=3
|
||||||
```
|
```
|
||||||
|
|
||||||
### NEAR AI Provider
|
### NEAR AI Provider
|
||||||
@@ -249,7 +321,51 @@ Session tokens have the format `sess_xxx` (37 characters). They are authenticate
|
|||||||
|
|
||||||
## Database
|
## Database
|
||||||
|
|
||||||
Single migration in `migrations/V1__initial.sql`. Tables:
|
IronClaw supports two database backends, selected at compile time via Cargo feature flags and at runtime via the `DATABASE_BACKEND` environment variable.
|
||||||
|
|
||||||
|
**IMPORTANT: All new features that touch persistence MUST support both backends.** Implement the operation as a method on the `Database` trait in `src/db/mod.rs`, then add the implementation in both `src/db/postgres.rs` (delegate to Store/Repository) and `src/db/libsql_backend.rs` (native SQL).
|
||||||
|
|
||||||
|
### Backends
|
||||||
|
|
||||||
|
| Backend | Feature Flag | Default | Use Case |
|
||||||
|
|---------|-------------|---------|----------|
|
||||||
|
| PostgreSQL | `postgres` (default) | Yes | Production, existing deployments |
|
||||||
|
| libSQL/Turso | `libsql` | No | Zero-dependency local mode, edge, Turso cloud |
|
||||||
|
|
||||||
|
```bash
|
||||||
|
# Build with PostgreSQL only (default)
|
||||||
|
cargo build
|
||||||
|
|
||||||
|
# Build with libSQL only
|
||||||
|
cargo build --no-default-features --features libsql
|
||||||
|
|
||||||
|
# Build with both backends available
|
||||||
|
cargo build --features "postgres,libsql"
|
||||||
|
```
|
||||||
|
|
||||||
|
### Database Trait
|
||||||
|
|
||||||
|
The `Database` trait (`src/db/mod.rs`) defines ~60 async methods covering all persistence:
|
||||||
|
- Conversations, messages, metadata
|
||||||
|
- Jobs, actions, LLM calls, estimation snapshots
|
||||||
|
- Sandbox jobs, job events
|
||||||
|
- Routines, routine runs
|
||||||
|
- Tool failures, settings
|
||||||
|
- Workspace: documents, chunks, hybrid search
|
||||||
|
|
||||||
|
Both backends implement this trait. PostgreSQL delegates to the existing `Store` + `Repository`. libSQL implements native SQLite-dialect SQL.
|
||||||
|
|
||||||
|
### Schema
|
||||||
|
|
||||||
|
**PostgreSQL:** `migrations/V1__initial.sql` (351 lines). Uses pgvector for embeddings, tsvector for FTS, PL/pgSQL functions. Managed by `refinery`.
|
||||||
|
|
||||||
|
**libSQL:** `src/db/libsql_migrations.rs` (consolidated schema, ~480 lines). Translates PG types:
|
||||||
|
- `UUID` -> `TEXT`, `TIMESTAMPTZ` -> `TEXT` (ISO-8601), `JSONB` -> `TEXT`
|
||||||
|
- `VECTOR(1536)` -> `F32_BLOB(1536)` with `libsql_vector_idx`
|
||||||
|
- `tsvector`/`ts_rank_cd` -> FTS5 virtual table with sync triggers
|
||||||
|
- PL/pgSQL functions -> SQLite triggers
|
||||||
|
|
||||||
|
**Tables (both backends):**
|
||||||
|
|
||||||
**Core:**
|
**Core:**
|
||||||
- `conversations` - Multi-channel conversation tracking
|
- `conversations` - Multi-channel conversation tracking
|
||||||
@@ -261,12 +377,41 @@ Single migration in `migrations/V1__initial.sql`. Tables:
|
|||||||
|
|
||||||
**Workspace/Memory:**
|
**Workspace/Memory:**
|
||||||
- `memory_documents` - Flexible path-based files (e.g., "context/vision.md", "daily/2024-01-15.md")
|
- `memory_documents` - Flexible path-based files (e.g., "context/vision.md", "daily/2024-01-15.md")
|
||||||
- `memory_chunks` - Chunked content with FTS (tsvector) and vector (pgvector) indexes
|
- `memory_chunks` - Chunked content with FTS and vector indexes
|
||||||
- `heartbeat_state` - Periodic execution tracking
|
- `heartbeat_state` - Periodic execution tracking
|
||||||
|
|
||||||
Requires pgvector extension: `CREATE EXTENSION IF NOT EXISTS vector;`
|
**Other:**
|
||||||
|
- `routines`, `routine_runs` - Scheduled/reactive execution
|
||||||
|
- `settings` - Per-user key-value settings
|
||||||
|
- `tool_failures` - Self-repair tracking
|
||||||
|
- `secrets`, `wasm_tools`, `tool_capabilities` - Extension infrastructure
|
||||||
|
|
||||||
Run migrations: `refinery migrate -c refinery.toml`
|
### Configuration
|
||||||
|
|
||||||
|
```bash
|
||||||
|
# Backend selection (default: postgres)
|
||||||
|
DATABASE_BACKEND=libsql
|
||||||
|
|
||||||
|
# PostgreSQL
|
||||||
|
DATABASE_URL=postgres://user:pass@localhost/ironclaw
|
||||||
|
|
||||||
|
# libSQL (embedded)
|
||||||
|
LIBSQL_PATH=~/.ironclaw/ironclaw.db # Default path
|
||||||
|
|
||||||
|
# libSQL (Turso cloud sync)
|
||||||
|
LIBSQL_URL=libsql://your-db.turso.io
|
||||||
|
LIBSQL_AUTH_TOKEN=your-token # Required when LIBSQL_URL is set
|
||||||
|
```
|
||||||
|
|
||||||
|
### Current Limitations (libSQL backend)
|
||||||
|
|
||||||
|
- **Workspace/memory system** not yet wired through Database trait (requires Store migration)
|
||||||
|
- **Secrets store** not yet available (still requires PostgresSecretsStore)
|
||||||
|
- **Hybrid search** uses FTS5 only (vector search via libsql_vector_idx not yet implemented)
|
||||||
|
- **Settings reload from DB** skipped (Config::from_db requires Store)
|
||||||
|
- No incremental migration versioning (schema is CREATE IF NOT EXISTS, no ALTER TABLE support yet)
|
||||||
|
- **No encryption at rest** -- The local SQLite database file stores conversation content, job data, workspace memory, and other application data in plaintext. Only secrets (API tokens, credentials) are encrypted via AES-256-GCM before storage. Users handling sensitive data should use full-disk encryption (FileVault, LUKS, BitLocker) or consider the PostgreSQL backend with TDE/encrypted storage.
|
||||||
|
- **JSON merge patch vs path-targeted update** -- The libSQL backend uses RFC 7396 JSON Merge Patch (`json_patch`) for metadata updates, while PostgreSQL uses path-targeted `jsonb_set`. Merge patch replaces top-level keys entirely, which may drop nested keys not present in the patch. Callers should avoid relying on partial nested object updates in metadata fields.
|
||||||
|
|
||||||
## Safety Layer
|
## Safety Layer
|
||||||
|
|
||||||
@@ -297,13 +442,14 @@ Key test patterns:
|
|||||||
|
|
||||||
## Current Limitations / TODOs
|
## Current Limitations / TODOs
|
||||||
|
|
||||||
1. **Slack/Telegram channels** - Stubs only, need implementation
|
1. **Domain-specific tools** - `marketplace.rs`, `restaurant.rs`, `taskrabbit.rs`, `ecommerce.rs` return placeholder responses; need real API integrations
|
||||||
2. **Domain-specific tools** - `marketplace.rs`, `restaurant.rs`, `taskrabbit.rs`, `ecommerce.rs` return placeholder responses; need real API integrations
|
2. **Integration tests** - Need testcontainers setup for PostgreSQL
|
||||||
3. **Integration tests** - Need testcontainers setup for PostgreSQL
|
3. **MCP stdio transport** - Only HTTP transport implemented
|
||||||
4. **MCP stdio transport** - Only HTTP transport implemented
|
4. **WIT bindgen integration** - Auto-extract tool description/schema from WASM modules (stubbed)
|
||||||
5. **WIT bindgen integration** - Auto-extract tool description/schema from WASM modules (stubbed)
|
5. **Capability granting after tool build** - Built tools get empty capabilities; need UX for granting HTTP/secrets access
|
||||||
6. **Capability granting after tool build** - Built tools get empty capabilities; need UX for granting HTTP/secrets access
|
6. **Tool versioning workflow** - No version tracking or rollback for dynamically built tools
|
||||||
7. **Tool versioning workflow** - No version tracking or rollback for dynamically built tools
|
7. **Webhook trigger endpoint** - Routines webhook trigger not yet exposed in web gateway
|
||||||
|
8. **Full channel status view** - Gateway status widget exists, but no per-channel connection dashboard
|
||||||
|
|
||||||
### Completed
|
### Completed
|
||||||
|
|
||||||
@@ -320,6 +466,14 @@ Key test patterns:
|
|||||||
- ✅ **Tool approval enforcement** - Tools with `requires_approval()` (shell, http, file write/patch, build_software) now gate execution, track auto-approved tools per session
|
- ✅ **Tool approval enforcement** - Tools with `requires_approval()` (shell, http, file write/patch, build_software) now gate execution, track auto-approved tools per session
|
||||||
- ✅ **Tool definition refresh** - Tool definitions refreshed each iteration so newly built tools become visible in same session
|
- ✅ **Tool definition refresh** - Tool definitions refreshed each iteration so newly built tools become visible in same session
|
||||||
- ✅ **Worker tool call handling** - Uses `respond_with_tools()` to properly execute tool calls when `select_tools()` returns empty
|
- ✅ **Worker tool call handling** - Uses `respond_with_tools()` to properly execute tool calls when `select_tools()` returns empty
|
||||||
|
- ✅ **Gateway control plane** - Web gateway with 40+ API endpoints, SSE/WebSocket
|
||||||
|
- ✅ **Web Control UI** - Browser-based dashboard with chat, memory, jobs, logs, extensions, routines
|
||||||
|
- ✅ **Slack/Telegram channels** - Implemented as WASM tools
|
||||||
|
- ✅ **Docker sandbox** - Orchestrator/worker containers with per-job auth
|
||||||
|
- ✅ **Claude Code mode** - Delegate jobs to Claude CLI inside containers
|
||||||
|
- ✅ **Routines system** - Cron, event, webhook, and manual triggers with guardrails
|
||||||
|
- ✅ **Extension management** - Install, auth, activate MCP/WASM extensions via CLI and web UI
|
||||||
|
- ✅ **libSQL/Turso backend** - Database trait abstraction (`src/db/`), feature-gated dual backend support (postgres/libsql), embedded SQLite for zero-dependency local mode
|
||||||
|
|
||||||
## Adding a New Tool
|
## Adding a New Tool
|
||||||
|
|
||||||
@@ -476,6 +630,22 @@ RUST_LOG=ironclaw::agent=debug cargo run
|
|||||||
RUST_LOG=ironclaw=debug,tower_http=debug cargo run
|
RUST_LOG=ironclaw=debug,tower_http=debug cargo run
|
||||||
```
|
```
|
||||||
|
|
||||||
|
## Module Specifications
|
||||||
|
|
||||||
|
Some modules have a `README.md` that serves as the authoritative specification
|
||||||
|
for that module's behavior. When modifying code in a module that has a spec:
|
||||||
|
|
||||||
|
1. **Read the spec first** before making changes
|
||||||
|
2. **Code follows spec**: if the spec says X, the code must do X
|
||||||
|
3. **Update both sides**: if you change behavior, update the spec to match;
|
||||||
|
if you're implementing a spec change, update the code to match
|
||||||
|
4. **Spec is the tiebreaker**: when code and spec disagree, the spec is correct
|
||||||
|
(unless the spec is clearly outdated, in which case fix the spec first)
|
||||||
|
|
||||||
|
| Module | Spec File |
|
||||||
|
|--------|-----------|
|
||||||
|
| `src/setup/` | `src/setup/README.md` |
|
||||||
|
|
||||||
## Code Style
|
## Code Style
|
||||||
|
|
||||||
- Use `crate::` imports, not `super::`
|
- Use `crate::` imports, not `super::`
|
||||||
@@ -484,6 +654,37 @@ RUST_LOG=ironclaw=debug,tower_http=debug cargo run
|
|||||||
- Keep functions focused, extract helpers when logic is reused
|
- Keep functions focused, extract helpers when logic is reused
|
||||||
- Comments for non-obvious logic only
|
- Comments for non-obvious logic only
|
||||||
|
|
||||||
|
## Review & Fix Discipline
|
||||||
|
|
||||||
|
Hard-won lessons from code review -- follow these when fixing bugs or addressing review feedback.
|
||||||
|
|
||||||
|
### Fix the pattern, not just the instance
|
||||||
|
When a reviewer flags a bug (e.g., TOCTOU race in INSERT + SELECT-back), search the entire codebase for all instances of that same pattern. A fix in `SecretsStore::create()` that doesn't also fix `WasmToolStore::store()` is half a fix.
|
||||||
|
|
||||||
|
### Propagate architectural fixes to satellite types
|
||||||
|
If a core type changes its concurrency model (e.g., `LibSqlBackend` switches to connection-per-operation), every type that was handed a resource from the old model (e.g., `LibSqlSecretsStore`, `LibSqlWasmToolStore` holding a single `Connection`) must also be updated. Grep for the old type across the codebase.
|
||||||
|
|
||||||
|
### Schema translation is more than DDL
|
||||||
|
When translating a database schema between backends (PostgreSQL to libSQL, etc.), check for:
|
||||||
|
- **Indexes** -- diff `CREATE INDEX` statements between the two schemas
|
||||||
|
- **Seed data** -- check for `INSERT INTO` in migrations (e.g., `leak_detection_patterns`)
|
||||||
|
- **Semantic differences** -- document where SQL functions behave differently (e.g., `json_patch` vs `jsonb_set`)
|
||||||
|
|
||||||
|
### Feature flag testing
|
||||||
|
When adding feature-gated code, test compilation with each feature in isolation:
|
||||||
|
```bash
|
||||||
|
cargo check # default features
|
||||||
|
cargo check --no-default-features --features libsql # libsql only
|
||||||
|
cargo check --all-features # all features
|
||||||
|
```
|
||||||
|
Dead code behind the wrong `#[cfg]` gate will only show up when building with a single feature.
|
||||||
|
|
||||||
|
### Mechanical verification before committing
|
||||||
|
Run these checks on changed files before committing:
|
||||||
|
- `grep -rnE '\.unwrap\(|\.expect\(' <files>` -- no panics in production
|
||||||
|
- `grep -rn 'super::' <files>` -- use `crate::` imports
|
||||||
|
- If you fixed a pattern bug, `grep` for other instances of that pattern across `src/`
|
||||||
|
|
||||||
## Workspace & Memory System
|
## Workspace & Memory System
|
||||||
|
|
||||||
Inspired by [OpenClaw](https://github.com/openclaw/openclaw), the workspace provides persistent memory for agents with a flexible filesystem-like structure.
|
Inspired by [OpenClaw](https://github.com/openclaw/openclaw), the workspace provides persistent memory for agents with a flexible filesystem-like structure.
|
||||||
@@ -558,7 +759,7 @@ Four tools for LLM use:
|
|||||||
|
|
||||||
### Hybrid Search (RRF)
|
### Hybrid Search (RRF)
|
||||||
|
|
||||||
Combines full-text search (PostgreSQL `ts_rank_cd`) and vector similarity (pgvector cosine) using Reciprocal Rank Fusion:
|
Combines full-text search and vector similarity using Reciprocal Rank Fusion:
|
||||||
|
|
||||||
```
|
```
|
||||||
score(d) = Σ 1/(k + rank(d)) for each method where d appears
|
score(d) = Σ 1/(k + rank(d)) for each method where d appears
|
||||||
@@ -566,6 +767,10 @@ score(d) = Σ 1/(k + rank(d)) for each method where d appears
|
|||||||
|
|
||||||
Default k=60. Results from both methods are combined, with documents appearing in both getting boosted scores.
|
Default k=60. Results from both methods are combined, with documents appearing in both getting boosted scores.
|
||||||
|
|
||||||
|
**Backend differences:**
|
||||||
|
- **PostgreSQL:** `ts_rank_cd` for FTS, pgvector cosine distance for vectors, full RRF
|
||||||
|
- **libSQL:** FTS5 for keyword search only (vector search via `libsql_vector_idx` not yet wired)
|
||||||
|
|
||||||
### Heartbeat System
|
### Heartbeat System
|
||||||
|
|
||||||
Proactive periodic execution (default: 30 minutes):
|
Proactive periodic execution (default: 30 minutes):
|
||||||
|
|||||||
Generated
+1022
-67
File diff suppressed because it is too large
Load Diff
+90
-12
@@ -1,10 +1,19 @@
|
|||||||
[package]
|
[package]
|
||||||
name = "ironclaw"
|
name = "ironclaw"
|
||||||
version = "0.1.0"
|
version = "0.3.0"
|
||||||
edition = "2024"
|
edition = "2024"
|
||||||
rust-version = "1.85"
|
rust-version = "1.92"
|
||||||
description = "Secure personal AI assistant that protects your data and expands its capabilities on the fly"
|
description = "Secure personal AI assistant that protects your data and expands its capabilities on the fly"
|
||||||
|
authors = ["NEAR AI <[email protected]>"]
|
||||||
license = "MIT OR Apache-2.0"
|
license = "MIT OR Apache-2.0"
|
||||||
|
homepage = "https://github.com/nearai/ironclaw"
|
||||||
|
repository = "https://github.com/nearai/ironclaw"
|
||||||
|
|
||||||
|
[package.metadata.wix]
|
||||||
|
upgrade-guid = "D0156E61-BA37-451E-8AB9-1A2ECCCFA48F"
|
||||||
|
path-guid = "F90B6EA6-87F7-499B-BB19-CF55DE1EB339"
|
||||||
|
license = false
|
||||||
|
eula = false
|
||||||
|
|
||||||
[dependencies]
|
[dependencies]
|
||||||
# Async runtime
|
# Async runtime
|
||||||
@@ -13,17 +22,20 @@ tokio-stream = { version = "0.1", features = ["sync"] }
|
|||||||
futures = "0.3"
|
futures = "0.3"
|
||||||
|
|
||||||
# HTTP client
|
# HTTP client
|
||||||
reqwest = { version = "0.12", default-features = false, features = ["json", "rustls-tls", "stream"] }
|
reqwest = { version = "0.12", default-features = false, features = ["json", "rustls-tls-native-roots", "stream"] }
|
||||||
|
|
||||||
# Serialization
|
# Serialization
|
||||||
serde = { version = "1", features = ["derive"] }
|
serde = { version = "1", features = ["derive"] }
|
||||||
serde_json = "1"
|
serde_json = "1"
|
||||||
|
|
||||||
# Database
|
# Database - PostgreSQL (default, feature-gated)
|
||||||
deadpool-postgres = "0.14"
|
deadpool-postgres = { version = "0.14", optional = true }
|
||||||
tokio-postgres = { version = "0.7", features = ["with-uuid-1", "with-chrono-0_4", "with-serde_json-1"] }
|
tokio-postgres = { version = "0.7", features = ["with-uuid-1", "with-chrono-0_4", "with-serde_json-1"], optional = true }
|
||||||
postgres-types = { version = "0.2", features = ["with-serde_json-1"] }
|
postgres-types = { version = "0.2", features = ["with-serde_json-1"], optional = true }
|
||||||
refinery = { version = "0.8", features = ["tokio-postgres"] }
|
refinery = { version = "0.8", features = ["tokio-postgres"], optional = true }
|
||||||
|
|
||||||
|
# Database - libSQL/Turso (optional embedded database)
|
||||||
|
libsql = { version = "0.6", optional = true, default-features = false, features = ["core", "replication"] }
|
||||||
|
|
||||||
# Error handling
|
# Error handling
|
||||||
thiserror = "2"
|
thiserror = "2"
|
||||||
@@ -39,7 +51,7 @@ dotenvy = "0.15"
|
|||||||
# Core types
|
# Core types
|
||||||
uuid = { version = "1", features = ["v4", "serde"] }
|
uuid = { version = "1", features = ["v4", "serde"] }
|
||||||
chrono = { version = "0.4", features = ["serde"] }
|
chrono = { version = "0.4", features = ["serde"] }
|
||||||
rust_decimal = { version = "1", features = ["serde", "serde-with-str", "db-tokio-postgres", "maths"] }
|
rust_decimal = { version = "1", features = ["serde", "serde-with-str", "maths"] }
|
||||||
rust_decimal_macros = "1"
|
rust_decimal_macros = "1"
|
||||||
|
|
||||||
# Async traits
|
# Async traits
|
||||||
@@ -58,17 +70,22 @@ axum = { version = "0.8", features = ["ws"] }
|
|||||||
tower = "0.5"
|
tower = "0.5"
|
||||||
tower-http = { version = "0.6", features = ["trace", "cors"] }
|
tower-http = { version = "0.6", features = ["trace", "cors"] }
|
||||||
|
|
||||||
|
# Cron scheduling for routines
|
||||||
|
cron = "0.13"
|
||||||
|
|
||||||
# Safety/sanitization
|
# Safety/sanitization
|
||||||
regex = "1"
|
regex = "1"
|
||||||
aho-corasick = "1"
|
aho-corasick = "1"
|
||||||
|
|
||||||
# Filesystem paths
|
# Filesystem paths
|
||||||
dirs = "6"
|
dirs = "6"
|
||||||
|
fs4 = "0.6"
|
||||||
|
|
||||||
# Secrecy for sensitive values
|
# Secrecy for sensitive values
|
||||||
secrecy = { version = "0.10", features = ["serde"] }
|
secrecy = { version = "0.10", features = ["serde"] }
|
||||||
|
|
||||||
# URL encoding for OAuth flow
|
# URL parsing and encoding
|
||||||
|
url = "2"
|
||||||
urlencoding = "2"
|
urlencoding = "2"
|
||||||
|
|
||||||
# Open URLs in browser
|
# Open URLs in browser
|
||||||
@@ -76,7 +93,7 @@ open = "5"
|
|||||||
|
|
||||||
# Vector embeddings for semantic search
|
# Vector embeddings for semantic search
|
||||||
# The postgres feature provides ToSql/FromSql for postgres-types (shared by tokio-postgres)
|
# The postgres feature provides ToSql/FromSql for postgres-types (shared by tokio-postgres)
|
||||||
pgvector = { version = "0.4", features = ["postgres"] }
|
pgvector = { version = "0.4", features = ["postgres"], optional = true }
|
||||||
|
|
||||||
# WASM sandbox for untrusted tool execution
|
# WASM sandbox for untrusted tool execution
|
||||||
wasmtime = { version = "28", features = ["component-model"] }
|
wasmtime = { version = "28", features = ["component-model"] }
|
||||||
@@ -89,6 +106,10 @@ hkdf = "0.12"
|
|||||||
sha2 = "0.10"
|
sha2 = "0.10"
|
||||||
blake3 = "1"
|
blake3 = "1"
|
||||||
rand = "0.8"
|
rand = "0.8"
|
||||||
|
subtle = "2" # Constant-time comparisons for token validation
|
||||||
|
|
||||||
|
# Multi-provider LLM support
|
||||||
|
rig-core = "0.30"
|
||||||
|
|
||||||
# Docker sandbox
|
# Docker sandbox
|
||||||
bollard = "0.18"
|
bollard = "0.18"
|
||||||
@@ -99,6 +120,7 @@ hyper-util = { version = "0.1", features = ["server", "tokio", "http1", "http2"]
|
|||||||
http-body-util = "0.1"
|
http-body-util = "0.1"
|
||||||
bytes = "1"
|
bytes = "1"
|
||||||
base64 = "0.22.1"
|
base64 = "0.22.1"
|
||||||
|
mime_guess = "2.0.5"
|
||||||
|
|
||||||
# macOS keychain
|
# macOS keychain
|
||||||
[target.'cfg(target_os = "macos")'.dependencies]
|
[target.'cfg(target_os = "macos")'.dependencies]
|
||||||
@@ -117,5 +139,61 @@ pretty_assertions = "1"
|
|||||||
tempfile = "3"
|
tempfile = "3"
|
||||||
|
|
||||||
[features]
|
[features]
|
||||||
default = []
|
default = ["postgres", "libsql"]
|
||||||
|
postgres = [
|
||||||
|
"dep:deadpool-postgres",
|
||||||
|
"dep:tokio-postgres",
|
||||||
|
"dep:postgres-types",
|
||||||
|
"dep:refinery",
|
||||||
|
"dep:pgvector",
|
||||||
|
"rust_decimal/db-tokio-postgres",
|
||||||
|
]
|
||||||
|
libsql = ["dep:libsql"]
|
||||||
integration = []
|
integration = []
|
||||||
|
|
||||||
|
[[example]]
|
||||||
|
name = "test_heartbeat"
|
||||||
|
required-features = ["postgres"]
|
||||||
|
|
||||||
|
# The profile that 'cargo dist' will build with
|
||||||
|
[profile.dist]
|
||||||
|
inherits = "release"
|
||||||
|
lto = "thin"
|
||||||
|
|
||||||
|
# Config for 'dist'
|
||||||
|
[workspace.metadata.dist]
|
||||||
|
# The preferred dist version to use in CI (Cargo.toml SemVer syntax)
|
||||||
|
cargo-dist-version = "0.30.3"
|
||||||
|
# CI backends to support
|
||||||
|
ci = "github"
|
||||||
|
# The installers to generate for each app
|
||||||
|
installers = ["shell", "powershell", "npm", "msi"]
|
||||||
|
# Publish jobs to run in CI
|
||||||
|
publish-jobs = []
|
||||||
|
# Target platforms to build apps for (Rust target-triple syntax)
|
||||||
|
targets = [
|
||||||
|
"aarch64-apple-darwin",
|
||||||
|
"aarch64-unknown-linux-gnu",
|
||||||
|
"x86_64-apple-darwin",
|
||||||
|
"x86_64-unknown-linux-gnu",
|
||||||
|
"x86_64-pc-windows-msvc",
|
||||||
|
]
|
||||||
|
# The archive format to use for windows builds (defaults .zip)
|
||||||
|
windows-archive = ".tar.gz"
|
||||||
|
# The archive format to use for non-windows builds (defaults .tar.xz)
|
||||||
|
unix-archive = ".tar.gz"
|
||||||
|
# Which actions to run on pull requests
|
||||||
|
pr-run-mode = "skip"
|
||||||
|
# Path that installers should place binaries in
|
||||||
|
install-path = "CARGO_HOME"
|
||||||
|
# Whether to install an updater program
|
||||||
|
install-updater = true
|
||||||
|
# Cache intermediate build artifacts to speed up the release pipelines
|
||||||
|
cache-builds = true
|
||||||
|
|
||||||
|
[workspace.metadata.dist.github-custom-runners]
|
||||||
|
aarch64-unknown-linux-gnu = "ubuntu-24.04-arm"
|
||||||
|
x86_64-unknown-linux-gnu = "ubuntu-22.04"
|
||||||
|
x86_64-pc-windows-msvc = "windows-2022"
|
||||||
|
x86_64-apple-darwin = "macos-15-intel"
|
||||||
|
aarch64-apple-darwin = "macos-14"
|
||||||
|
|||||||
+46
@@ -0,0 +1,46 @@
|
|||||||
|
# Multi-stage Dockerfile for the IronClaw agent (cloud deployment).
|
||||||
|
#
|
||||||
|
# Build:
|
||||||
|
# docker build --platform linux/amd64 -t ironclaw:latest .
|
||||||
|
#
|
||||||
|
# Run:
|
||||||
|
# docker run --env-file .env -p 3000:3000 ironclaw:latest
|
||||||
|
|
||||||
|
# Stage 1: Build
|
||||||
|
FROM rust:1.92-slim-bookworm AS builder
|
||||||
|
|
||||||
|
RUN apt-get update && apt-get install -y --no-install-recommends \
|
||||||
|
pkg-config libssl-dev cmake gcc g++ \
|
||||||
|
&& rm -rf /var/lib/apt/lists/*
|
||||||
|
|
||||||
|
WORKDIR /app
|
||||||
|
|
||||||
|
# Copy manifests first for layer caching
|
||||||
|
COPY Cargo.toml Cargo.lock ./
|
||||||
|
|
||||||
|
# Copy source and build artifacts
|
||||||
|
COPY src/ src/
|
||||||
|
COPY migrations/ migrations/
|
||||||
|
COPY wit/ wit/
|
||||||
|
|
||||||
|
RUN cargo build --release --bin ironclaw
|
||||||
|
|
||||||
|
# Stage 2: Runtime
|
||||||
|
FROM debian:bookworm-slim
|
||||||
|
|
||||||
|
RUN apt-get update && apt-get install -y --no-install-recommends \
|
||||||
|
ca-certificates libssl3 \
|
||||||
|
&& rm -rf /var/lib/apt/lists/*
|
||||||
|
|
||||||
|
COPY --from=builder /app/target/release/ironclaw /usr/local/bin/ironclaw
|
||||||
|
COPY --from=builder /app/migrations /app/migrations
|
||||||
|
|
||||||
|
# Non-root user
|
||||||
|
RUN useradd -m -u 1000 -s /bin/bash ironclaw
|
||||||
|
USER ironclaw
|
||||||
|
|
||||||
|
EXPOSE 3000
|
||||||
|
|
||||||
|
ENV RUST_LOG=ironclaw=info
|
||||||
|
|
||||||
|
ENTRYPOINT ["ironclaw"]
|
||||||
@@ -0,0 +1,63 @@
|
|||||||
|
# Multi-stage Dockerfile for the IronClaw worker container.
|
||||||
|
#
|
||||||
|
# This image runs the ironclaw binary in worker mode inside Docker containers.
|
||||||
|
# The orchestrator creates instances of this image for sandboxed job execution.
|
||||||
|
#
|
||||||
|
# Build:
|
||||||
|
# docker build -f Dockerfile.worker -t ironclaw-worker .
|
||||||
|
#
|
||||||
|
# The image includes common development tools so workers can build software,
|
||||||
|
# run tests, and execute shell commands.
|
||||||
|
|
||||||
|
FROM rust:1.92-bookworm AS builder
|
||||||
|
|
||||||
|
WORKDIR /build
|
||||||
|
COPY . .
|
||||||
|
|
||||||
|
# Build only the ironclaw binary (release mode)
|
||||||
|
RUN cargo build --release --bin ironclaw
|
||||||
|
|
||||||
|
# ---
|
||||||
|
|
||||||
|
FROM debian:bookworm-slim
|
||||||
|
|
||||||
|
# Install common development tools
|
||||||
|
RUN apt-get update && apt-get install -y --no-install-recommends \
|
||||||
|
ca-certificates \
|
||||||
|
curl \
|
||||||
|
git \
|
||||||
|
build-essential \
|
||||||
|
pkg-config \
|
||||||
|
libssl-dev \
|
||||||
|
nodejs \
|
||||||
|
npm \
|
||||||
|
python3 \
|
||||||
|
python3-pip \
|
||||||
|
python3-venv \
|
||||||
|
&& rm -rf /var/lib/apt/lists/*
|
||||||
|
|
||||||
|
# Install Rust toolchain for the sandbox user
|
||||||
|
ENV RUSTUP_HOME=/usr/local/rustup \
|
||||||
|
CARGO_HOME=/usr/local/cargo \
|
||||||
|
PATH=/usr/local/cargo/bin:$PATH
|
||||||
|
RUN curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh -s -- -y --default-toolchain 1.92.0 \
|
||||||
|
&& chmod -R a+r /usr/local/rustup /usr/local/cargo
|
||||||
|
|
||||||
|
# Install Claude Code CLI (for claude-bridge mode)
|
||||||
|
RUN npm install -g @anthropic-ai/claude-code@latest
|
||||||
|
|
||||||
|
# Copy the binary
|
||||||
|
COPY --from=builder /build/target/release/ironclaw /usr/local/bin/ironclaw
|
||||||
|
|
||||||
|
# Create non-root user (UID 1000 matches the orchestrator's container config)
|
||||||
|
RUN useradd -m -u 1000 -s /bin/bash sandbox \
|
||||||
|
&& mkdir -p /workspace \
|
||||||
|
&& chown sandbox:sandbox /workspace \
|
||||||
|
&& mkdir -p /home/sandbox/.claude \
|
||||||
|
&& chown sandbox:sandbox /home/sandbox/.claude
|
||||||
|
|
||||||
|
USER sandbox
|
||||||
|
WORKDIR /workspace
|
||||||
|
|
||||||
|
# The orchestrator passes the full command via Docker cmd.
|
||||||
|
ENTRYPOINT ["ironclaw"]
|
||||||
+49
-39
@@ -16,8 +16,8 @@ This document tracks feature parity between IronClaw (Rust implementation) and O
|
|||||||
|
|
||||||
| Feature | OpenClaw | IronClaw | Notes |
|
| Feature | OpenClaw | IronClaw | Notes |
|
||||||
|---------|----------|----------|-------|
|
|---------|----------|----------|-------|
|
||||||
| Hub-and-spoke architecture | ✅ | 🚧 | IronClaw has channels but no central gateway |
|
| Hub-and-spoke architecture | ✅ | ✅ | Web gateway as central hub |
|
||||||
| WebSocket control plane | ✅ | ❌ | Gateway with ws://127.0.0.1:18789 |
|
| WebSocket control plane | ✅ | ✅ | Gateway with WebSocket + SSE |
|
||||||
| Single-user system | ✅ | ✅ | |
|
| Single-user system | ✅ | ✅ | |
|
||||||
| Multi-agent routing | ✅ | ❌ | Workspace isolation per-agent |
|
| Multi-agent routing | ✅ | ❌ | Workspace isolation per-agent |
|
||||||
| Session-based messaging | ✅ | ✅ | Per-sender sessions |
|
| Session-based messaging | ✅ | ✅ | Per-sender sessions |
|
||||||
@@ -31,19 +31,19 @@ This document tracks feature parity between IronClaw (Rust implementation) and O
|
|||||||
|
|
||||||
| Feature | OpenClaw | IronClaw | Notes |
|
| Feature | OpenClaw | IronClaw | Notes |
|
||||||
|---------|----------|----------|-------|
|
|---------|----------|----------|-------|
|
||||||
| Gateway control plane | ✅ | ❌ | Central WebSocket server |
|
| Gateway control plane | ✅ | ✅ | Web gateway with 40+ API endpoints |
|
||||||
| HTTP endpoints for Control UI | ✅ | ❌ | Web dashboard |
|
| HTTP endpoints for Control UI | ✅ | ✅ | Web dashboard with chat, memory, jobs, logs, extensions |
|
||||||
| Channel connection lifecycle | ✅ | 🚧 | ChannelManager handles streams |
|
| Channel connection lifecycle | ✅ | ✅ | ChannelManager + WebSocket tracker |
|
||||||
| Session management/routing | ✅ | ✅ | SessionManager exists |
|
| Session management/routing | ✅ | ✅ | SessionManager exists |
|
||||||
| Configuration hot-reload | ✅ | ❌ | |
|
| Configuration hot-reload | ✅ | ❌ | |
|
||||||
| Network modes (loopback/LAN/remote) | ✅ | 🚧 | HTTP only |
|
| Network modes (loopback/LAN/remote) | ✅ | 🚧 | HTTP only |
|
||||||
| OpenAI-compatible HTTP API | ✅ | ❌ | /v1/chat/completions |
|
| OpenAI-compatible HTTP API | ✅ | ✅ | /v1/chat/completions |
|
||||||
| Canvas hosting | ✅ | ❌ | Agent-driven UI |
|
| Canvas hosting | ✅ | ❌ | Agent-driven UI |
|
||||||
| Gateway lock (PID-based) | ✅ | ❌ | |
|
| Gateway lock (PID-based) | ✅ | ❌ | |
|
||||||
| launchd/systemd integration | ✅ | ❌ | |
|
| launchd/systemd integration | ✅ | ❌ | |
|
||||||
| Bonjour/mDNS discovery | ✅ | ❌ | |
|
| Bonjour/mDNS discovery | ✅ | ❌ | |
|
||||||
| Tailscale integration | ✅ | ❌ | |
|
| Tailscale integration | ✅ | ❌ | |
|
||||||
| Health check endpoints | ✅ | ❌ | |
|
| Health check endpoints | ✅ | ✅ | /api/health + /api/gateway/status |
|
||||||
| `doctor` diagnostics | ✅ | ❌ | |
|
| `doctor` diagnostics | ✅ | ❌ | |
|
||||||
|
|
||||||
### Owner: _Unassigned_
|
### Owner: _Unassigned_
|
||||||
@@ -59,14 +59,14 @@ This document tracks feature parity between IronClaw (Rust implementation) and O
|
|||||||
| REPL (simple) | ✅ | ✅ | - | For testing |
|
| REPL (simple) | ✅ | ✅ | - | For testing |
|
||||||
| WASM channels | ❌ | ✅ | - | IronClaw innovation |
|
| WASM channels | ❌ | ✅ | - | IronClaw innovation |
|
||||||
| WhatsApp | ✅ | ❌ | P1 | Baileys (Web) |
|
| WhatsApp | ✅ | ❌ | P1 | Baileys (Web) |
|
||||||
| Telegram | ✅ | ❌ | P1 | grammY (Bot API) |
|
| Telegram | ✅ | ✅ | - | WASM channel(MTProto), DM pairing, caption, /start, bot_username |
|
||||||
| Discord | ✅ | ❌ | P2 | discord.js |
|
| Discord | ✅ | ❌ | P2 | discord.js |
|
||||||
| Signal | ✅ | ❌ | P2 | signal-cli |
|
| Signal | ✅ | ❌ | P2 | signal-cli |
|
||||||
| Slack | ✅ | 🚧 | P1 | Stub exists, needs implementation |
|
| Slack | ✅ | ✅ | - | WASM tool |
|
||||||
| iMessage | ✅ | ❌ | P3 | BlueBubbles recommended |
|
| iMessage | ✅ | ❌ | P3 | BlueBubbles recommended |
|
||||||
| Feishu/Lark | ✅ | ❌ | P3 | |
|
| Feishu/Lark | ✅ | ❌ | P3 | |
|
||||||
| LINE | ✅ | ❌ | P3 | |
|
| LINE | ✅ | ❌ | P3 | |
|
||||||
| WebChat | ✅ | ❌ | P2 | Browser-based chat |
|
| WebChat | ✅ | ✅ | - | Web gateway chat |
|
||||||
| Matrix | ✅ | ❌ | P3 | E2EE support |
|
| Matrix | ✅ | ❌ | P3 | E2EE support |
|
||||||
| Mattermost | ✅ | ❌ | P3 | |
|
| Mattermost | ✅ | ❌ | P3 | |
|
||||||
| Google Chat | ✅ | ❌ | P3 | |
|
| Google Chat | ✅ | ❌ | P3 | |
|
||||||
@@ -79,13 +79,13 @@ This document tracks feature parity between IronClaw (Rust implementation) and O
|
|||||||
|
|
||||||
| Feature | OpenClaw | IronClaw | Notes |
|
| Feature | OpenClaw | IronClaw | Notes |
|
||||||
|---------|----------|----------|-------|
|
|---------|----------|----------|-------|
|
||||||
| DM pairing codes | ✅ | ❌ | Verification for unknown senders |
|
| DM pairing codes | ✅ | ✅ | `ironclaw pairing list/approve`, host APIs |
|
||||||
| Allowlist/blocklist | ✅ | ❌ | Per-channel access control |
|
| Allowlist/blocklist | ✅ | 🚧 | allow_from + pairing store |
|
||||||
| Self-message bypass | ✅ | ❌ | Own messages skip pairing |
|
| Self-message bypass | ✅ | ❌ | Own messages skip pairing |
|
||||||
| Mention-based activation | ✅ | ❌ | Configurable patterns |
|
| Mention-based activation | ✅ | ✅ | bot_username + respond_to_all_group_messages |
|
||||||
| Per-group tool policies | ✅ | ❌ | Allow/deny specific tools |
|
| Per-group tool policies | ✅ | ❌ | Allow/deny specific tools |
|
||||||
| Thread isolation | ✅ | ✅ | Separate sessions per thread |
|
| Thread isolation | ✅ | ✅ | Separate sessions per thread |
|
||||||
| Per-channel media limits | ✅ | ❌ | |
|
| Per-channel media limits | ✅ | 🚧 | Caption support for media; no size limits |
|
||||||
| Typing indicators | ✅ | 🚧 | TUI shows status |
|
| Typing indicators | ✅ | 🚧 | TUI shows status |
|
||||||
|
|
||||||
### Owner: _Unassigned_
|
### Owner: _Unassigned_
|
||||||
@@ -99,17 +99,17 @@ This document tracks feature parity between IronClaw (Rust implementation) and O
|
|||||||
| `run` (agent) | ✅ | ✅ | - | Default command |
|
| `run` (agent) | ✅ | ✅ | - | Default command |
|
||||||
| `tool install/list/remove` | ✅ | ✅ | - | WASM tools |
|
| `tool install/list/remove` | ✅ | ✅ | - | WASM tools |
|
||||||
| `gateway start/stop` | ✅ | ❌ | P2 | |
|
| `gateway start/stop` | ✅ | ❌ | P2 | |
|
||||||
| `onboard` (wizard) | ✅ | ❌ | P2 | Interactive setup |
|
| `onboard` (wizard) | ✅ | ✅ | - | Interactive setup |
|
||||||
| `tui` | ✅ | ✅ | - | Ratatui TUI |
|
| `tui` | ✅ | ✅ | - | Ratatui TUI |
|
||||||
| `config` | ✅ | ❌ | P2 | Read/write config |
|
| `config` | ✅ | ✅ | - | Read/write config |
|
||||||
| `channels` | ✅ | ❌ | P2 | Channel management |
|
| `channels` | ✅ | ❌ | P2 | Channel management |
|
||||||
| `models` | ✅ | 🚧 | - | Model selector in TUI |
|
| `models` | ✅ | 🚧 | - | Model selector in TUI |
|
||||||
| `status` | ✅ | ❌ | P2 | System status |
|
| `status` | ✅ | ✅ | - | System status |
|
||||||
| `agents` | ✅ | ❌ | P3 | Multi-agent management |
|
| `agents` | ✅ | ❌ | P3 | Multi-agent management |
|
||||||
| `sessions` | ✅ | ❌ | P3 | Session listing |
|
| `sessions` | ✅ | ❌ | P3 | Session listing |
|
||||||
| `memory` | ✅ | ❌ | P2 | Memory search CLI |
|
| `memory` | ✅ | ✅ | - | Memory search CLI |
|
||||||
| `skills` | ✅ | ❌ | P3 | Agent skills |
|
| `skills` | ✅ | ❌ | P3 | Agent skills |
|
||||||
| `pairing` | ✅ | ❌ | P3 | Node pairing |
|
| `pairing` | ✅ | ✅ | - | list/approve for channel DM pairing |
|
||||||
| `nodes` | ✅ | ❌ | P3 | Device management |
|
| `nodes` | ✅ | ❌ | P3 | Device management |
|
||||||
| `plugins` | ✅ | ❌ | P3 | Plugin management |
|
| `plugins` | ✅ | ❌ | P3 | Plugin management |
|
||||||
| `hooks` | ✅ | ❌ | P2 | Lifecycle hooks |
|
| `hooks` | ✅ | ❌ | P2 | Lifecycle hooks |
|
||||||
@@ -132,8 +132,8 @@ This document tracks feature parity between IronClaw (Rust implementation) and O
|
|||||||
| Feature | OpenClaw | IronClaw | Notes |
|
| Feature | OpenClaw | IronClaw | Notes |
|
||||||
|---------|----------|----------|-------|
|
|---------|----------|----------|-------|
|
||||||
| Pi agent runtime | ✅ | ➖ | IronClaw uses custom runtime |
|
| Pi agent runtime | ✅ | ➖ | IronClaw uses custom runtime |
|
||||||
| RPC-based execution | ✅ | 🚧 | Worker isolation |
|
| RPC-based execution | ✅ | ✅ | Orchestrator/worker pattern |
|
||||||
| Multi-provider failover | ✅ | ❌ | Provider fallback chains |
|
| Multi-provider failover | ✅ | ✅ | `FailoverProvider` tries providers sequentially on retryable errors |
|
||||||
| Per-sender sessions | ✅ | ✅ | |
|
| Per-sender sessions | ✅ | ✅ | |
|
||||||
| Global sessions | ✅ | ❌ | Optional shared context |
|
| Global sessions | ✅ | ❌ | Optional shared context |
|
||||||
| Session pruning | ✅ | ❌ | Auto cleanup old sessions |
|
| Session pruning | ✅ | ❌ | Auto cleanup old sessions |
|
||||||
@@ -164,7 +164,7 @@ This document tracks feature parity between IronClaw (Rust implementation) and O
|
|||||||
| AWS Bedrock | ✅ | ❌ | P3 | |
|
| AWS Bedrock | ✅ | ❌ | P3 | |
|
||||||
| Google Gemini | ✅ | ❌ | P3 | |
|
| Google Gemini | ✅ | ❌ | P3 | |
|
||||||
| OpenRouter | ✅ | ❌ | P3 | |
|
| OpenRouter | ✅ | ❌ | P3 | |
|
||||||
| Ollama (local) | ✅ | ❌ | P2 | Local models |
|
| Ollama (local) | ✅ | ✅ | - | via `rig::providers::ollama` (full support) |
|
||||||
| node-llama-cpp | ✅ | ➖ | - | N/A for Rust |
|
| node-llama-cpp | ✅ | ➖ | - | N/A for Rust |
|
||||||
| llama.cpp (native) | ❌ | 🔮 | P3 | Rust bindings |
|
| llama.cpp (native) | ❌ | 🔮 | P3 | Rust bindings |
|
||||||
|
|
||||||
@@ -173,7 +173,7 @@ This document tracks feature parity between IronClaw (Rust implementation) and O
|
|||||||
| Feature | OpenClaw | IronClaw | Notes |
|
| Feature | OpenClaw | IronClaw | Notes |
|
||||||
|---------|----------|----------|-------|
|
|---------|----------|----------|-------|
|
||||||
| Auto-discovery | ✅ | ❌ | |
|
| Auto-discovery | ✅ | ❌ | |
|
||||||
| Failover chains | ✅ | ❌ | Provider fallback |
|
| Failover chains | ✅ | ✅ | `FailoverProvider` with configurable `fallback_model` |
|
||||||
| Cooldown management | ✅ | ❌ | Skip failed providers |
|
| Cooldown management | ✅ | ❌ | Skip failed providers |
|
||||||
| Per-session model override | ✅ | ✅ | Model selector in TUI |
|
| Per-session model override | ✅ | ✅ | Model selector in TUI |
|
||||||
| Model selection UI | ✅ | ✅ | TUI keyboard shortcut |
|
| Model selection UI | ✅ | ✅ | TUI keyboard shortcut |
|
||||||
@@ -303,13 +303,13 @@ This document tracks feature parity between IronClaw (Rust implementation) and O
|
|||||||
|
|
||||||
| Feature | OpenClaw | IronClaw | Priority | Notes |
|
| Feature | OpenClaw | IronClaw | Priority | Notes |
|
||||||
|---------|----------|----------|----------|-------|
|
|---------|----------|----------|----------|-------|
|
||||||
| Control UI Dashboard | ✅ | ❌ | P2 | Web status/config |
|
| Control UI Dashboard | ✅ | ✅ | - | Web gateway with chat, memory, jobs, logs, extensions |
|
||||||
| Channel status view | ✅ | ❌ | P2 | |
|
| Channel status view | ✅ | 🚧 | P2 | Gateway status widget, full channel view pending |
|
||||||
| Agent management | ✅ | ❌ | P3 | |
|
| Agent management | ✅ | ❌ | P3 | |
|
||||||
| Model selection | ✅ | ✅ | - | TUI only |
|
| Model selection | ✅ | ✅ | - | TUI only |
|
||||||
| Config editing | ✅ | ❌ | P3 | |
|
| Config editing | ✅ | ❌ | P3 | |
|
||||||
| Debug/logs viewer | ✅ | ❌ | P3 | |
|
| Debug/logs viewer | ✅ | ✅ | - | Real-time log streaming with level/target filters |
|
||||||
| WebChat interface | ✅ | ❌ | P2 | Browser chat |
|
| WebChat interface | ✅ | ✅ | - | Web gateway chat with SSE/WebSocket |
|
||||||
| Canvas system (A2UI) | ✅ | ❌ | P3 | Agent-driven UI |
|
| Canvas system (A2UI) | ✅ | ❌ | P3 | Agent-driven UI |
|
||||||
|
|
||||||
### Owner: _Unassigned_
|
### Owner: _Unassigned_
|
||||||
@@ -320,13 +320,13 @@ This document tracks feature parity between IronClaw (Rust implementation) and O
|
|||||||
|
|
||||||
| Feature | OpenClaw | IronClaw | Priority | Notes |
|
| Feature | OpenClaw | IronClaw | Priority | Notes |
|
||||||
|---------|----------|----------|----------|-------|
|
|---------|----------|----------|----------|-------|
|
||||||
| Cron jobs | ✅ | ❌ | P2 | Schedule-based tasks |
|
| Cron jobs | ✅ | ✅ | - | Routines with cron trigger |
|
||||||
| Timezone support | ✅ | ❌ | P2 | |
|
| Timezone support | ✅ | ✅ | - | Via cron expressions |
|
||||||
| One-shot/recurring jobs | ✅ | ❌ | P2 | |
|
| One-shot/recurring jobs | ✅ | ✅ | - | Manual + cron triggers |
|
||||||
| `beforeInbound` hook | ✅ | ❌ | P2 | |
|
| `beforeInbound` hook | ✅ | ❌ | P2 | |
|
||||||
| `beforeOutbound` hook | ✅ | ❌ | P2 | |
|
| `beforeOutbound` hook | ✅ | ❌ | P2 | |
|
||||||
| `beforeToolCall` hook | ✅ | ❌ | P2 | |
|
| `beforeToolCall` hook | ✅ | ❌ | P2 | |
|
||||||
| `onMessage` hook | ✅ | ❌ | P2 | |
|
| `onMessage` hook | ✅ | ✅ | - | Routines with event trigger |
|
||||||
| `onSessionStart` hook | ✅ | ❌ | P2 | |
|
| `onSessionStart` hook | ✅ | ❌ | P2 | |
|
||||||
| `onSessionEnd` hook | ✅ | ❌ | P2 | |
|
| `onSessionEnd` hook | ✅ | ❌ | P2 | |
|
||||||
| `transcribeAudio` hook | ✅ | ❌ | P3 | |
|
| `transcribeAudio` hook | ✅ | ❌ | P3 | |
|
||||||
@@ -346,18 +346,18 @@ This document tracks feature parity between IronClaw (Rust implementation) and O
|
|||||||
|
|
||||||
| Feature | OpenClaw | IronClaw | Notes |
|
| Feature | OpenClaw | IronClaw | Notes |
|
||||||
|---------|----------|----------|-------|
|
|---------|----------|----------|-------|
|
||||||
| Gateway token auth | ✅ | 🚧 | HTTP webhook secret |
|
| Gateway token auth | ✅ | ✅ | Bearer token auth on web gateway |
|
||||||
| Device pairing | ✅ | ❌ | |
|
| Device pairing | ✅ | ❌ | |
|
||||||
| Tailscale identity | ✅ | ❌ | |
|
| Tailscale identity | ✅ | ❌ | |
|
||||||
| OAuth flows | ✅ | 🚧 | NEAR AI OAuth |
|
| OAuth flows | ✅ | 🚧 | NEAR AI OAuth |
|
||||||
| DM pairing verification | ✅ | ❌ | |
|
| DM pairing verification | ✅ | ✅ | ironclaw pairing approve, host APIs |
|
||||||
| Allowlist/blocklist | ✅ | ❌ | |
|
| Allowlist/blocklist | ✅ | 🚧 | allow_from + pairing store |
|
||||||
| Per-group tool policies | ✅ | ❌ | |
|
| Per-group tool policies | ✅ | ❌ | |
|
||||||
| Exec approvals | ✅ | ✅ | TUI overlay |
|
| Exec approvals | ✅ | ✅ | TUI overlay |
|
||||||
| TLS 1.3 minimum | ✅ | ✅ | reqwest rustls |
|
| TLS 1.3 minimum | ✅ | ✅ | reqwest rustls |
|
||||||
| SSRF protection | ✅ | ✅ | WASM allowlist |
|
| SSRF protection | ✅ | ✅ | WASM allowlist |
|
||||||
| Loopback-first | ✅ | 🚧 | HTTP binds 0.0.0.0 |
|
| Loopback-first | ✅ | 🚧 | HTTP binds 0.0.0.0 |
|
||||||
| Docker sandbox | ✅ | ❌ | Uses WASM sandbox |
|
| Docker sandbox | ✅ | ✅ | Orchestrator/worker containers |
|
||||||
| WASM sandbox | ❌ | ✅ | IronClaw innovation |
|
| WASM sandbox | ❌ | ✅ | IronClaw innovation |
|
||||||
| Tool policies | ✅ | ✅ | |
|
| Tool policies | ✅ | ✅ | |
|
||||||
| Elevated mode | ✅ | ❌ | |
|
| Elevated mode | ✅ | ❌ | |
|
||||||
@@ -397,6 +397,7 @@ This document tracks feature parity between IronClaw (Rust implementation) and O
|
|||||||
### P0 - Core (Already Done)
|
### P0 - Core (Already Done)
|
||||||
- ✅ TUI channel with approval overlays
|
- ✅ TUI channel with approval overlays
|
||||||
- ✅ HTTP webhook channel
|
- ✅ HTTP webhook channel
|
||||||
|
- ✅ DM pairing (ironclaw pairing list/approve, host APIs)
|
||||||
- ✅ WASM tool sandbox
|
- ✅ WASM tool sandbox
|
||||||
- ✅ Workspace/memory with hybrid search
|
- ✅ Workspace/memory with hybrid search
|
||||||
- ✅ Prompt injection defense
|
- ✅ Prompt injection defense
|
||||||
@@ -404,23 +405,32 @@ This document tracks feature parity between IronClaw (Rust implementation) and O
|
|||||||
- ✅ Session management
|
- ✅ Session management
|
||||||
- ✅ Context compaction
|
- ✅ Context compaction
|
||||||
- ✅ Model selection
|
- ✅ Model selection
|
||||||
|
- ✅ Gateway control plane + WebSocket
|
||||||
|
- ✅ Web Control UI (chat, memory, jobs, logs, extensions, routines)
|
||||||
|
- ✅ WebChat channel (web gateway)
|
||||||
|
- ✅ Slack channel (WASM tool)
|
||||||
|
- ✅ Telegram channel (WASM tool, MTProto)
|
||||||
|
- ✅ Docker sandbox (orchestrator/worker)
|
||||||
|
- ✅ Cron job scheduling (routines)
|
||||||
|
- ✅ CLI subcommands (onboard, config, status, memory)
|
||||||
|
- ✅ Gateway token auth
|
||||||
|
|
||||||
### P1 - High Priority
|
### P1 - High Priority
|
||||||
- ❌ Slack channel (real implementation)
|
- ❌ Slack channel (real implementation)
|
||||||
- ❌ Telegram channel
|
- ✅ Telegram channel (WASM, DM pairing, caption, /start)
|
||||||
- ❌ WhatsApp channel
|
- ❌ WhatsApp channel
|
||||||
- ❌ Multi-provider failover
|
- ✅ Multi-provider failover (`FailoverProvider` with retryable error classification)
|
||||||
- ❌ Gateway control plane + WebSocket
|
|
||||||
- ❌ Hooks system (beforeInbound, beforeToolCall, etc.)
|
- ❌ Hooks system (beforeInbound, beforeToolCall, etc.)
|
||||||
|
|
||||||
### P2 - Medium Priority
|
### P2 - Medium Priority
|
||||||
- ❌ Cron job scheduling
|
- ❌ Cron job scheduling
|
||||||
- ❌ Web Control UI
|
- ❌ Web Control UI
|
||||||
- ❌ WebChat channel
|
- ❌ WebChat channel
|
||||||
- ❌ Media handling (images, PDFs)
|
- 🚧 Media handling (caption support; no image/PDF processing)
|
||||||
- ❌ CLI subcommands (config, status, memory, doctor)
|
- ❌ CLI subcommands (config, status, memory, doctor)
|
||||||
- ❌ Ollama/local model support
|
- ❌ Ollama/local model support
|
||||||
- ❌ Configuration hot-reload
|
- ❌ Configuration hot-reload
|
||||||
|
- ❌ Webhook trigger endpoint in web gateway
|
||||||
|
|
||||||
### P3 - Lower Priority
|
### P3 - Lower Priority
|
||||||
- ❌ Discord channel
|
- ❌ Discord channel
|
||||||
|
|||||||
@@ -43,7 +43,10 @@ IronClaw is the AI assistant you can actually trust with your personal and profe
|
|||||||
|
|
||||||
### Always Available
|
### Always Available
|
||||||
|
|
||||||
- **Multi-channel** - REPL, HTTP webhooks, and extensible WASM channels (Telegram, Slack, and more)
|
- **Multi-channel** - REPL, HTTP webhooks, WASM channels (Telegram, Slack), and web gateway
|
||||||
|
- **Docker Sandbox** - Isolated container execution with per-job tokens and orchestrator/worker pattern
|
||||||
|
- **Web Gateway** - Browser UI with real-time SSE/WebSocket streaming
|
||||||
|
- **Routines** - Cron schedules, event triggers, webhook handlers for background automation
|
||||||
- **Heartbeat System** - Proactive background execution for monitoring and maintenance tasks
|
- **Heartbeat System** - Proactive background execution for monitoring and maintenance tasks
|
||||||
- **Parallel Jobs** - Handle multiple requests concurrently with isolated contexts
|
- **Parallel Jobs** - Handle multiple requests concurrently with isolated contexts
|
||||||
- **Self-repair** - Automatic detection and recovery of stuck operations
|
- **Self-repair** - Automatic detection and recovery of stuck operations
|
||||||
@@ -65,10 +68,41 @@ IronClaw is the AI assistant you can actually trust with your personal and profe
|
|||||||
### Prerequisites
|
### Prerequisites
|
||||||
|
|
||||||
- Rust 1.85+
|
- Rust 1.85+
|
||||||
- PostgreSQL 15+ with pgvector extension
|
- PostgreSQL 15+ with [pgvector](https://github.com/pgvector/pgvector) extension
|
||||||
- NEAR AI account (authentication handled via setup wizard)
|
- NEAR AI account (authentication handled via setup wizard)
|
||||||
|
|
||||||
### Build
|
## Download or Build
|
||||||
|
|
||||||
|
Visit [Releases page](https://github.com/nearai/ironclaw/releases/) to see the latest updates.
|
||||||
|
|
||||||
|
<details>
|
||||||
|
<summary>Install via Windows Installer (Windows)</summary>
|
||||||
|
|
||||||
|
Download the [Windows Installer](https://github.com/nearai/ironclaw/releases/latest/download/ironclaw-x86_64-pc-windows-msvc.msi) and run it.
|
||||||
|
|
||||||
|
</details>
|
||||||
|
|
||||||
|
<details>
|
||||||
|
<summary>Install via powershell script (Windows)</summary>
|
||||||
|
|
||||||
|
```sh
|
||||||
|
irm https://github.com/nearai/ironclaw/releases/latest/download/ironclaw-installer.ps1 | iex
|
||||||
|
```
|
||||||
|
|
||||||
|
</details>
|
||||||
|
|
||||||
|
<details>
|
||||||
|
<summary>Install via shell script (macOS, Linux, Windows/WSL)</summary>
|
||||||
|
|
||||||
|
```sh
|
||||||
|
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/nearai/ironclaw/releases/latest/download/ironclaw-installer.sh | sh
|
||||||
|
```
|
||||||
|
</details>
|
||||||
|
|
||||||
|
<details>
|
||||||
|
<summary>Compile the source code (Cargo on Windows, Linux, macOS)</summary>
|
||||||
|
|
||||||
|
Install it with `cargo`, just make sure you have [Rust](https://rustup.rs) installed on your computer.
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
# Clone the repository
|
# Clone the repository
|
||||||
@@ -82,6 +116,10 @@ cargo build --release
|
|||||||
cargo test
|
cargo test
|
||||||
```
|
```
|
||||||
|
|
||||||
|
For **full release** (after modifying channel sources), run `./scripts/build-all.sh` to rebuild channels first.
|
||||||
|
|
||||||
|
</details>
|
||||||
|
|
||||||
### Database Setup
|
### Database Setup
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
@@ -97,7 +135,7 @@ psql ironclaw -c "CREATE EXTENSION IF NOT EXISTS vector;"
|
|||||||
Run the setup wizard to configure IronClaw:
|
Run the setup wizard to configure IronClaw:
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
ironclaw setup
|
ironclaw onboard
|
||||||
```
|
```
|
||||||
|
|
||||||
The wizard handles database connection, NEAR AI authentication (via browser OAuth),
|
The wizard handles database connection, NEAR AI authentication (via browser OAuth),
|
||||||
@@ -143,37 +181,42 @@ External content passes through multiple security layers:
|
|||||||
## Architecture
|
## Architecture
|
||||||
|
|
||||||
```
|
```
|
||||||
┌─────────────────────────────────────────────────────────────────┐
|
┌────────────────────────────────────────────────────────────────┐
|
||||||
│ Channels │
|
│ Channels │
|
||||||
│ ┌──────┐ ┌──────┐ ┌──────────────┐ │
|
│ ┌──────┐ ┌──────┐ ┌─────────────┐ ┌─────────────┐ │
|
||||||
│ │ REPL │ │ HTTP │ │ WASM Channels│ │
|
│ │ REPL │ │ HTTP │ │WASM Channels│ │ Web Gateway │ │
|
||||||
│ └──┬───┘ └──┬───┘ └──────┬───────┘ │
|
│ └──┬───┘ └──┬───┘ └──────┬──────┘ │ (SSE + WS) │ │
|
||||||
│ └─────────┴─────────────┘ │
|
│ │ │ │ └──────┬──────┘ │
|
||||||
|
│ └─────────┴──────────────┴────────────────┘ │
|
||||||
│ │ │
|
│ │ │
|
||||||
│ ┌────▼────┐ │
|
│ ┌─────────▼─────────┐ │
|
||||||
│ │ Router │ Intent classification │
|
│ │ Agent Loop │ Intent routing │
|
||||||
│ └────┬────┘ │
|
│ └────┬──────────┬───┘ │
|
||||||
|
│ │ │ │
|
||||||
|
│ ┌──────────▼────┐ ┌──▼───────────────┐ │
|
||||||
|
│ │ Scheduler │ │ Routines Engine │ │
|
||||||
|
│ │(parallel jobs)│ │(cron, event, wh) │ │
|
||||||
|
│ └──────┬────────┘ └────────┬─────────┘ │
|
||||||
|
│ │ │ │
|
||||||
|
│ ┌─────────────┼────────────────────┘ │
|
||||||
|
│ │ │ │
|
||||||
|
│ ┌───▼─────┐ ┌────▼────────────────┐ │
|
||||||
|
│ │ Local │ │ Orchestrator │ │
|
||||||
|
│ │Workers │ │ ┌───────────────┐ │ │
|
||||||
|
│ │(in-proc)│ │ │ Docker Sandbox│ │ │
|
||||||
|
│ └───┬─────┘ │ │ Containers │ │ │
|
||||||
|
│ │ │ │ ┌───────────┐ │ │ │
|
||||||
|
│ │ │ │ │Worker / CC│ │ │ │
|
||||||
|
│ │ │ │ └───────────┘ │ │ │
|
||||||
|
│ │ │ └───────────────┘ │ │
|
||||||
|
│ │ └─────────┬───────────┘ │
|
||||||
|
│ └──────────────────┤ │
|
||||||
│ │ │
|
│ │ │
|
||||||
│ ┌──────────▼──────────┐ │
|
│ ┌───────────▼──────────┐ │
|
||||||
│ │ Scheduler │ Parallel job management │
|
|
||||||
│ └──────────┬──────────┘ │
|
|
||||||
│ │ │
|
|
||||||
│ ┌───────────────┼───────────────┐ │
|
|
||||||
│ ▼ ▼ ▼ │
|
|
||||||
│ ┌─────────┐ ┌─────────┐ ┌─────────┐ │
|
|
||||||
│ │ Worker │ │ Worker │ │ Worker │ LLM reasoning │
|
|
||||||
│ └────┬────┘ └────┬────┘ └────┬────┘ │
|
|
||||||
│ └───────────────┼───────────────┘ │
|
|
||||||
│ │ │
|
|
||||||
│ ┌──────────▼──────────┐ │
|
|
||||||
│ │ Tool Registry │ │
|
│ │ Tool Registry │ │
|
||||||
│ │ ┌───────────────┐ │ │
|
│ │ Built-in, MCP, WASM │ │
|
||||||
│ │ │ Built-in │ │ │
|
│ └──────────────────────┘ │
|
||||||
│ │ │ MCP │ │ │
|
└────────────────────────────────────────────────────────────────┘
|
||||||
│ │ │ WASM Sandbox │ │ │
|
|
||||||
│ │ └───────────────┘ │ │
|
|
||||||
│ └─────────────────────┘ │
|
|
||||||
└─────────────────────────────────────────────────────────────────┘
|
|
||||||
```
|
```
|
||||||
|
|
||||||
### Core Components
|
### Core Components
|
||||||
@@ -184,6 +227,9 @@ External content passes through multiple security layers:
|
|||||||
| **Router** | Classifies user intent (command, query, task) |
|
| **Router** | Classifies user intent (command, query, task) |
|
||||||
| **Scheduler** | Manages parallel job execution with priorities |
|
| **Scheduler** | Manages parallel job execution with priorities |
|
||||||
| **Worker** | Executes jobs with LLM reasoning and tool calls |
|
| **Worker** | Executes jobs with LLM reasoning and tool calls |
|
||||||
|
| **Orchestrator** | Container lifecycle, LLM proxying, per-job auth |
|
||||||
|
| **Web Gateway** | Browser UI with chat, memory, jobs, logs, extensions, routines |
|
||||||
|
| **Routines Engine** | Scheduled (cron) and reactive (event, webhook) background tasks |
|
||||||
| **Workspace** | Persistent memory with hybrid search |
|
| **Workspace** | Persistent memory with hybrid search |
|
||||||
| **Safety Layer** | Prompt injection defense and content sanitization |
|
| **Safety Layer** | Prompt injection defense and content sanitization |
|
||||||
|
|
||||||
@@ -191,7 +237,7 @@ External content passes through multiple security layers:
|
|||||||
|
|
||||||
```bash
|
```bash
|
||||||
# First-time setup (configures database, auth, etc.)
|
# First-time setup (configures database, auth, etc.)
|
||||||
ironclaw setup
|
ironclaw onboard
|
||||||
|
|
||||||
# Start interactive REPL
|
# Start interactive REPL
|
||||||
cargo run
|
cargo run
|
||||||
@@ -210,12 +256,16 @@ cargo fmt
|
|||||||
cargo clippy --all --benches --tests --examples --all-features
|
cargo clippy --all --benches --tests --examples --all-features
|
||||||
|
|
||||||
# Run tests
|
# Run tests
|
||||||
|
createdb ironclaw_test
|
||||||
cargo test
|
cargo test
|
||||||
|
|
||||||
# Run specific test
|
# Run specific test
|
||||||
cargo test test_name
|
cargo test test_name
|
||||||
```
|
```
|
||||||
|
|
||||||
|
- **Telegram channel**: See [docs/TELEGRAM_SETUP.md](docs/TELEGRAM_SETUP.md) for setup and DM pairing.
|
||||||
|
- **Changing channel sources**: Run `./channels-src/telegram/build.sh` before `cargo build` so the updated WASM is bundled.
|
||||||
|
|
||||||
## OpenClaw Heritage
|
## OpenClaw Heritage
|
||||||
|
|
||||||
IronClaw is a Rust reimplementation inspired by [OpenClaw](https://github.com/openclaw/openclaw). See [FEATURE_PARITY.md](FEATURE_PARITY.md) for the complete tracking matrix.
|
IronClaw is a Rust reimplementation inspired by [OpenClaw](https://github.com/openclaw/openclaw). See [FEATURE_PARITY.md](FEATURE_PARITY.md) for the complete tracking matrix.
|
||||||
|
|||||||
@@ -0,0 +1,106 @@
|
|||||||
|
//! Build script: compile Telegram channel WASM from source.
|
||||||
|
//!
|
||||||
|
//! Do not commit compiled WASM binaries — they are a supply chain risk.
|
||||||
|
//! This script builds telegram.wasm from channels-src/telegram before the main crate compiles.
|
||||||
|
//!
|
||||||
|
//! Reproducible build:
|
||||||
|
//! cargo build --release
|
||||||
|
//! (build.rs invokes the channel build automatically)
|
||||||
|
//!
|
||||||
|
//! Prerequisites: rustup target add wasm32-wasip2, cargo install wasm-tools
|
||||||
|
|
||||||
|
use std::env;
|
||||||
|
use std::path::PathBuf;
|
||||||
|
use std::process::Command;
|
||||||
|
|
||||||
|
fn main() {
|
||||||
|
let manifest_dir = env::var("CARGO_MANIFEST_DIR").unwrap();
|
||||||
|
let root = PathBuf::from(&manifest_dir);
|
||||||
|
let channel_dir = root.join("channels-src/telegram");
|
||||||
|
let wasm_out = channel_dir.join("telegram.wasm");
|
||||||
|
|
||||||
|
// Rerun when channel source or build script changes
|
||||||
|
println!("cargo:rerun-if-changed=channels-src/telegram/src");
|
||||||
|
println!("cargo:rerun-if-changed=channels-src/telegram/Cargo.toml");
|
||||||
|
println!("cargo:rerun-if-changed=wit/channel.wit");
|
||||||
|
|
||||||
|
if !channel_dir.is_dir() {
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
// Build WASM module
|
||||||
|
let status = match Command::new("cargo")
|
||||||
|
.args([
|
||||||
|
"build",
|
||||||
|
"--release",
|
||||||
|
"--target",
|
||||||
|
"wasm32-wasip2",
|
||||||
|
"--manifest-path",
|
||||||
|
channel_dir.join("Cargo.toml").to_str().unwrap(),
|
||||||
|
])
|
||||||
|
.current_dir(&root)
|
||||||
|
.status()
|
||||||
|
{
|
||||||
|
Ok(s) => s,
|
||||||
|
Err(_) => {
|
||||||
|
eprintln!(
|
||||||
|
"cargo:warning=Telegram channel build failed. Run: ./channels-src/telegram/build.sh"
|
||||||
|
);
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
|
if !status.success() {
|
||||||
|
eprintln!(
|
||||||
|
"cargo:warning=Telegram channel build failed. Run: ./channels-src/telegram/build.sh"
|
||||||
|
);
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
let raw_wasm = channel_dir.join("target/wasm32-wasip2/release/telegram_channel.wasm");
|
||||||
|
if !raw_wasm.exists() {
|
||||||
|
eprintln!(
|
||||||
|
"cargo:warning=Telegram WASM output not found at {:?}",
|
||||||
|
raw_wasm
|
||||||
|
);
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
// Convert to component and strip (wasm-tools)
|
||||||
|
let component_ok = Command::new("wasm-tools")
|
||||||
|
.args([
|
||||||
|
"component",
|
||||||
|
"new",
|
||||||
|
raw_wasm.to_str().unwrap(),
|
||||||
|
"-o",
|
||||||
|
wasm_out.to_str().unwrap(),
|
||||||
|
])
|
||||||
|
.current_dir(&root)
|
||||||
|
.status()
|
||||||
|
.map(|s| s.success())
|
||||||
|
.unwrap_or(false);
|
||||||
|
|
||||||
|
if !component_ok {
|
||||||
|
// Fallback: copy raw module if wasm-tools unavailable
|
||||||
|
if std::fs::copy(&raw_wasm, &wasm_out).is_err() {
|
||||||
|
eprintln!("cargo:warning=wasm-tools not found. Run: cargo install wasm-tools");
|
||||||
|
}
|
||||||
|
} else {
|
||||||
|
// Strip debug info (use temp file to avoid clobbering)
|
||||||
|
let stripped = wasm_out.with_extension("wasm.stripped");
|
||||||
|
let strip_ok = Command::new("wasm-tools")
|
||||||
|
.args([
|
||||||
|
"strip",
|
||||||
|
wasm_out.to_str().unwrap(),
|
||||||
|
"-o",
|
||||||
|
stripped.to_str().unwrap(),
|
||||||
|
])
|
||||||
|
.current_dir(&root)
|
||||||
|
.status()
|
||||||
|
.map(|s| s.success())
|
||||||
|
.unwrap_or(false);
|
||||||
|
if strip_ok {
|
||||||
|
let _ = std::fs::rename(&stripped, &wasm_out);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,23 @@
|
|||||||
|
[package]
|
||||||
|
name = "discord-channel"
|
||||||
|
version = "0.1.0"
|
||||||
|
edition = "2021"
|
||||||
|
description = "Discord channel for IronClaw"
|
||||||
|
license = "MIT OR Apache-2.0"
|
||||||
|
publish = false
|
||||||
|
|
||||||
|
[dependencies]
|
||||||
|
serde = { version = "1.0", features = ["derive"] }
|
||||||
|
serde_json = "1.0"
|
||||||
|
wit-bindgen = "0.41.0"
|
||||||
|
|
||||||
|
[lib]
|
||||||
|
crate-type = ["cdylib"]
|
||||||
|
|
||||||
|
[profile.release]
|
||||||
|
strip = true
|
||||||
|
opt-level = "s"
|
||||||
|
lto = true
|
||||||
|
codegen-units = 1
|
||||||
|
|
||||||
|
|
||||||
@@ -0,0 +1,121 @@
|
|||||||
|
# Discord Channel for IronClaw
|
||||||
|
|
||||||
|
WASM channel for Discord integration - handle slash commands and button interactions via webhooks.
|
||||||
|
|
||||||
|
## Features
|
||||||
|
|
||||||
|
- **Slash Commands** - Process Discord slash commands
|
||||||
|
- **Button Interactions** - Handle button clicks
|
||||||
|
- **Thread Support** - Respond in threads
|
||||||
|
- **DM Support** - Handle direct messages
|
||||||
|
|
||||||
|
## Setup
|
||||||
|
|
||||||
|
1. Create a Discord Application at <https://discord.com/developers/applications>
|
||||||
|
2. Create a Bot and get the token
|
||||||
|
3. Set up Interactions URL to point to your IronClaw instance
|
||||||
|
4. Copy the Application ID and Public Key
|
||||||
|
5. Store in IronClaw secrets:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
ironclaw secret set discord_bot_token YOUR_BOT_TOKEN
|
||||||
|
```
|
||||||
|
|
||||||
|
**Note:** The `discord_bot_token` secret is the only value read directly by this
|
||||||
|
Discord channel WASM component. The `discord_app_id` and `discord_public_key`
|
||||||
|
secrets are used by the IronClaw host (for example, to verify Discord
|
||||||
|
interaction signatures and manage slash command registration) and are not
|
||||||
|
accessed from the WASM module itself.
|
||||||
|
|
||||||
|
## Discord Configuration
|
||||||
|
|
||||||
|
### Register Slash Commands
|
||||||
|
|
||||||
|
```bash
|
||||||
|
curl -X POST \
|
||||||
|
-H "Authorization: Bot YOUR_BOT_TOKEN" \
|
||||||
|
-H "Content-Type: application/json" \
|
||||||
|
https://discord.com/api/v10/applications/YOUR_APP_ID/commands \
|
||||||
|
-d '{
|
||||||
|
"name": "ask",
|
||||||
|
"description": "Ask the AI agent",
|
||||||
|
"options": [{
|
||||||
|
"name": "question",
|
||||||
|
"description": "Your question",
|
||||||
|
"type": 3,
|
||||||
|
"required": true
|
||||||
|
}]
|
||||||
|
}'
|
||||||
|
```
|
||||||
|
|
||||||
|
### Set Interactions Endpoint
|
||||||
|
|
||||||
|
In your Discord app settings, set:
|
||||||
|
|
||||||
|
- Interactions Endpoint URL: `https://your-ironclaw.com/webhook/discord`
|
||||||
|
|
||||||
|
## Usage Examples
|
||||||
|
|
||||||
|
### Slash Command
|
||||||
|
|
||||||
|
User types: `/ask question: What is the weather?`
|
||||||
|
|
||||||
|
The agent receives:
|
||||||
|
|
||||||
|
```text
|
||||||
|
User: @username
|
||||||
|
Content: /ask question: What is the weather?
|
||||||
|
```
|
||||||
|
|
||||||
|
### Button Click
|
||||||
|
|
||||||
|
When a user clicks a button in a message, the agent receives:
|
||||||
|
|
||||||
|
```text
|
||||||
|
User: @username
|
||||||
|
Content: [Button clicked] Original message content
|
||||||
|
```
|
||||||
|
|
||||||
|
## Error Handling
|
||||||
|
|
||||||
|
If an internal error occurs (e.g., metadata serialization failure), the tool attempts to send an ephemeral message to the user:
|
||||||
|
|
||||||
|
```text
|
||||||
|
❌ Internal Error: Failed to process command metadata.
|
||||||
|
```
|
||||||
|
|
||||||
|
Check the host logs for detailed error information.
|
||||||
|
|
||||||
|
## Advanced Usage
|
||||||
|
|
||||||
|
### Embeds
|
||||||
|
|
||||||
|
To send embeds, include an `embeds` array in the `metadata_json` field of the agent's response. The structure should match the Discord API `embed` object.
|
||||||
|
|
||||||
|
## Troubleshooting
|
||||||
|
|
||||||
|
### "Invalid Signature"
|
||||||
|
|
||||||
|
- Check that `discord_public_key` is set correctly in IronClaw secrets.
|
||||||
|
- This validation happens on the host before reaching the WASM.
|
||||||
|
|
||||||
|
### "401 Unauthorized"
|
||||||
|
|
||||||
|
- Check that `discord_bot_token` is set correctly in IronClaw secrets.
|
||||||
|
- Ensure the bot is added to the server.
|
||||||
|
|
||||||
|
### "Interaction Failed"
|
||||||
|
|
||||||
|
- The interaction might have timed out (Discord requires a response within 3 seconds).
|
||||||
|
- The `interactions_endpoint_url` might be unreachable.
|
||||||
|
|
||||||
|
## Building
|
||||||
|
|
||||||
|
```bash
|
||||||
|
cd channels-src/discord
|
||||||
|
cargo build --target wasm32-wasi --release
|
||||||
|
```
|
||||||
|
|
||||||
|
## License
|
||||||
|
|
||||||
|
MIT/Apache-2.0
|
||||||
@@ -0,0 +1,39 @@
|
|||||||
|
{
|
||||||
|
"type": "channel",
|
||||||
|
"name": "discord",
|
||||||
|
"description": "Discord Gateway/Webhook channel for handling slash commands, buttons, and messages",
|
||||||
|
"capabilities": {
|
||||||
|
"http": {
|
||||||
|
"allowlist": [
|
||||||
|
{ "host": "discord.com", "path_prefix": "/api/v10" }
|
||||||
|
],
|
||||||
|
"credentials": {
|
||||||
|
"discord_bot_token": {
|
||||||
|
"secret_name": "discord_bot_token",
|
||||||
|
"location": { "type": "header", "header_name": "Authorization", "prefix": "Bot " },
|
||||||
|
"host_patterns": ["discord.com"]
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"rate_limit": {
|
||||||
|
"requests_per_minute": 60,
|
||||||
|
"requests_per_hour": 3600
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"secrets": {
|
||||||
|
"allowed_names": ["discord_bot_token", "discord_*"]
|
||||||
|
},
|
||||||
|
"channel": {
|
||||||
|
"allowed_paths": ["/webhook/discord"],
|
||||||
|
"allow_polling": false,
|
||||||
|
"callback_timeout_secs": 45,
|
||||||
|
"workspace_prefix": "channels/discord/",
|
||||||
|
"emit_rate_limit": {
|
||||||
|
"messages_per_minute": 100,
|
||||||
|
"messages_per_hour": 5000
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"config": {
|
||||||
|
"require_signature_verification": true
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,476 @@
|
|||||||
|
//! Discord Gateway/Webhook channel for IronClaw.
|
||||||
|
//!
|
||||||
|
//! This WASM component implements the channel interface for handling Discord
|
||||||
|
//! interactions via webhooks and sending messages back to Discord.
|
||||||
|
//!
|
||||||
|
//! # Features
|
||||||
|
//!
|
||||||
|
//! - URL verification for Discord interactions
|
||||||
|
//! - Slash command handling
|
||||||
|
//! - Message event parsing (@mentions, DMs)
|
||||||
|
//! - Thread support for conversations
|
||||||
|
//! - Response posting via Discord Web API
|
||||||
|
//! - Automatic message truncation (> 2000 chars)
|
||||||
|
//!
|
||||||
|
//! # Security
|
||||||
|
//!
|
||||||
|
//! - Signature validation is handled by the host (webhook secrets)
|
||||||
|
//! - Bot token is injected by host during HTTP requests
|
||||||
|
//! - WASM never sees raw credentials
|
||||||
|
|
||||||
|
wit_bindgen::generate!({
|
||||||
|
world: "sandboxed-channel",
|
||||||
|
path: "../../wit/channel.wit",
|
||||||
|
});
|
||||||
|
|
||||||
|
use serde::{Deserialize, Serialize};
|
||||||
|
|
||||||
|
use exports::near::agent::channel::{
|
||||||
|
AgentResponse, ChannelConfig, Guest, HttpEndpointConfig, IncomingHttpRequest,
|
||||||
|
OutgoingHttpResponse, StatusUpdate,
|
||||||
|
};
|
||||||
|
use near::agent::channel_host::{self, EmittedMessage};
|
||||||
|
|
||||||
|
/// Discord interaction wrapper.
|
||||||
|
#[derive(Debug, Deserialize)]
|
||||||
|
struct DiscordInteraction {
|
||||||
|
/// Interaction type (1=Ping, 2=ApplicationCommand, 3=MessageComponent)
|
||||||
|
#[serde(rename = "type")]
|
||||||
|
interaction_type: u8,
|
||||||
|
|
||||||
|
/// Interaction ID
|
||||||
|
id: String,
|
||||||
|
|
||||||
|
/// Application ID
|
||||||
|
application_id: String,
|
||||||
|
|
||||||
|
/// Guild ID (if in server)
|
||||||
|
#[allow(dead_code)] // Part of API payload, currently unused
|
||||||
|
guild_id: Option<String>,
|
||||||
|
|
||||||
|
/// Channel ID
|
||||||
|
channel_id: Option<String>,
|
||||||
|
|
||||||
|
/// Member info (if in server)
|
||||||
|
member: Option<DiscordMember>,
|
||||||
|
|
||||||
|
/// User info (if DM)
|
||||||
|
user: Option<DiscordUser>,
|
||||||
|
|
||||||
|
/// Command data (for slash commands)
|
||||||
|
data: Option<DiscordCommandData>,
|
||||||
|
|
||||||
|
/// Message (for component interactions)
|
||||||
|
message: Option<DiscordMessage>,
|
||||||
|
|
||||||
|
/// Token for responding
|
||||||
|
token: String,
|
||||||
|
}
|
||||||
|
|
||||||
|
#[derive(Debug, Deserialize, Clone)]
|
||||||
|
struct DiscordMember {
|
||||||
|
user: DiscordUser,
|
||||||
|
#[allow(dead_code)] // Part of API payload, currently unused
|
||||||
|
nick: Option<String>,
|
||||||
|
}
|
||||||
|
|
||||||
|
#[derive(Debug, Deserialize, Clone)]
|
||||||
|
struct DiscordUser {
|
||||||
|
id: String,
|
||||||
|
username: String,
|
||||||
|
global_name: Option<String>,
|
||||||
|
}
|
||||||
|
|
||||||
|
#[derive(Debug, Deserialize, Clone)]
|
||||||
|
struct DiscordCommandData {
|
||||||
|
#[allow(dead_code)] // Part of API payload, currently unused
|
||||||
|
id: String,
|
||||||
|
name: String,
|
||||||
|
options: Option<Vec<DiscordCommandOption>>,
|
||||||
|
}
|
||||||
|
|
||||||
|
#[derive(Debug, Deserialize, Clone)]
|
||||||
|
struct DiscordCommandOption {
|
||||||
|
name: String,
|
||||||
|
value: serde_json::Value,
|
||||||
|
}
|
||||||
|
|
||||||
|
#[derive(Debug, Deserialize, Clone)]
|
||||||
|
struct DiscordMessage {
|
||||||
|
#[allow(dead_code)] // Part of API payload, currently unused
|
||||||
|
id: String,
|
||||||
|
content: String,
|
||||||
|
channel_id: String,
|
||||||
|
#[allow(dead_code)] // Part of API payload, currently unused
|
||||||
|
author: DiscordUser,
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Metadata stored with emitted messages for response routing.
|
||||||
|
#[derive(Debug, Serialize, Deserialize)]
|
||||||
|
struct DiscordMessageMetadata {
|
||||||
|
/// Discord channel ID
|
||||||
|
channel_id: String,
|
||||||
|
|
||||||
|
/// Interaction ID for followups
|
||||||
|
interaction_id: String,
|
||||||
|
|
||||||
|
/// Interaction token for responding
|
||||||
|
token: String,
|
||||||
|
|
||||||
|
/// Application ID
|
||||||
|
application_id: String,
|
||||||
|
|
||||||
|
/// Thread ID (for forum threads)
|
||||||
|
thread_id: Option<String>,
|
||||||
|
}
|
||||||
|
|
||||||
|
struct DiscordChannel;
|
||||||
|
|
||||||
|
impl Guest for DiscordChannel {
|
||||||
|
fn on_start(_config_json: String) -> Result<ChannelConfig, String> {
|
||||||
|
channel_host::log(channel_host::LogLevel::Info, "Discord channel starting");
|
||||||
|
|
||||||
|
Ok(ChannelConfig {
|
||||||
|
display_name: "Discord".to_string(),
|
||||||
|
http_endpoints: vec![HttpEndpointConfig {
|
||||||
|
path: "/webhook/discord".to_string(),
|
||||||
|
methods: vec!["POST".to_string()],
|
||||||
|
require_secret: true,
|
||||||
|
}],
|
||||||
|
poll: None,
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
|
fn on_http_request(req: IncomingHttpRequest) -> OutgoingHttpResponse {
|
||||||
|
let body_str = match std::str::from_utf8(&req.body) {
|
||||||
|
Ok(s) => s,
|
||||||
|
Err(_) => {
|
||||||
|
return json_response(400, serde_json::json!({"error": "Invalid UTF-8 body"}));
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
|
let interaction: DiscordInteraction = match serde_json::from_str(body_str) {
|
||||||
|
Ok(i) => i,
|
||||||
|
Err(e) => {
|
||||||
|
channel_host::log(
|
||||||
|
channel_host::LogLevel::Error,
|
||||||
|
&format!("Failed to parse Discord interaction: {}", e),
|
||||||
|
);
|
||||||
|
return json_response(400, serde_json::json!({"error": "Invalid interaction"}));
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
|
match interaction.interaction_type {
|
||||||
|
// Ping - Discord verification
|
||||||
|
1 => {
|
||||||
|
channel_host::log(channel_host::LogLevel::Info, "Responding to Discord ping");
|
||||||
|
json_response(200, serde_json::json!({"type": 1}))
|
||||||
|
}
|
||||||
|
|
||||||
|
// Application Command (slash command)
|
||||||
|
2 => {
|
||||||
|
handle_slash_command(&interaction);
|
||||||
|
json_response(
|
||||||
|
200,
|
||||||
|
serde_json::json!({
|
||||||
|
"type": 5,
|
||||||
|
"data": {
|
||||||
|
"content": "🤔 Thinking..."
|
||||||
|
}
|
||||||
|
}),
|
||||||
|
)
|
||||||
|
}
|
||||||
|
|
||||||
|
// Message Component (buttons, selects)
|
||||||
|
3 => {
|
||||||
|
if let Some(ref message) = interaction.message {
|
||||||
|
handle_message_component(&interaction, message);
|
||||||
|
}
|
||||||
|
json_response(200, serde_json::json!({"type": 6}))
|
||||||
|
}
|
||||||
|
|
||||||
|
_ => {
|
||||||
|
channel_host::log(
|
||||||
|
channel_host::LogLevel::Warn,
|
||||||
|
&format!(
|
||||||
|
"Unknown Discord interaction type: {}",
|
||||||
|
interaction.interaction_type
|
||||||
|
),
|
||||||
|
);
|
||||||
|
json_response(200, serde_json::json!({"type": 6}))
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
fn on_poll() {}
|
||||||
|
|
||||||
|
fn on_respond(response: AgentResponse) -> Result<(), String> {
|
||||||
|
let metadata: DiscordMessageMetadata = serde_json::from_str(&response.metadata_json)
|
||||||
|
.map_err(|e| format!("Failed to parse metadata: {}", e))?;
|
||||||
|
|
||||||
|
// Use webhook endpoint for followup
|
||||||
|
let url = format!(
|
||||||
|
"https://discord.com/api/v10/webhooks/{}/{}",
|
||||||
|
metadata.application_id, metadata.token
|
||||||
|
);
|
||||||
|
|
||||||
|
// Truncate content to 2000 characters to comply with Discord limits
|
||||||
|
let content = truncate_message(&response.content);
|
||||||
|
|
||||||
|
let mut payload = serde_json::json!({
|
||||||
|
"content": content,
|
||||||
|
});
|
||||||
|
|
||||||
|
// Check for embeds in metadata
|
||||||
|
if let Ok(meta_json) = serde_json::from_str::<serde_json::Value>(&response.metadata_json) {
|
||||||
|
if let Some(embeds) = meta_json.get("embeds") {
|
||||||
|
payload["embeds"] = embeds.clone();
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
let payload_bytes =
|
||||||
|
serde_json::to_vec(&payload).map_err(|e| format!("Failed to serialize: {}", e))?;
|
||||||
|
|
||||||
|
let headers = serde_json::json!({
|
||||||
|
"Content-Type": "application/json"
|
||||||
|
});
|
||||||
|
|
||||||
|
let result = channel_host::http_request(
|
||||||
|
"POST",
|
||||||
|
&url,
|
||||||
|
&headers.to_string(),
|
||||||
|
Some(&payload_bytes),
|
||||||
|
None,
|
||||||
|
);
|
||||||
|
|
||||||
|
match result {
|
||||||
|
Ok(http_response) => {
|
||||||
|
if http_response.status >= 200 && http_response.status < 300 {
|
||||||
|
channel_host::log(channel_host::LogLevel::Debug, "Posted followup to Discord");
|
||||||
|
Ok(())
|
||||||
|
} else {
|
||||||
|
let body_str = String::from_utf8_lossy(&http_response.body);
|
||||||
|
Err(format!(
|
||||||
|
"Discord API error: {} - {}",
|
||||||
|
http_response.status, body_str
|
||||||
|
))
|
||||||
|
}
|
||||||
|
}
|
||||||
|
Err(e) => Err(format!("HTTP request failed: {}", e)),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
fn on_status(_update: StatusUpdate) {}
|
||||||
|
|
||||||
|
fn on_shutdown() {
|
||||||
|
channel_host::log(
|
||||||
|
channel_host::LogLevel::Info,
|
||||||
|
"Discord channel shutting down",
|
||||||
|
);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
fn handle_slash_command(interaction: &DiscordInteraction) {
|
||||||
|
let user = interaction
|
||||||
|
.member
|
||||||
|
.as_ref()
|
||||||
|
.map(|m| &m.user)
|
||||||
|
.or(interaction.user.as_ref());
|
||||||
|
let user_id = user.map(|u| u.id.clone()).unwrap_or_default();
|
||||||
|
let user_name = user
|
||||||
|
.map(|u| {
|
||||||
|
u.global_name
|
||||||
|
.as_ref()
|
||||||
|
.filter(|s| !s.is_empty())
|
||||||
|
.unwrap_or(&u.username)
|
||||||
|
.clone()
|
||||||
|
})
|
||||||
|
.unwrap_or_default();
|
||||||
|
|
||||||
|
let channel_id = interaction.channel_id.clone().unwrap_or_default();
|
||||||
|
|
||||||
|
let command_name = interaction
|
||||||
|
.data
|
||||||
|
.as_ref()
|
||||||
|
.map(|d| d.name.clone())
|
||||||
|
.unwrap_or_default();
|
||||||
|
let options = interaction.data.as_ref().and_then(|d| d.options.clone());
|
||||||
|
|
||||||
|
let content = if let Some(opts) = options {
|
||||||
|
let opt_str = opts
|
||||||
|
.iter()
|
||||||
|
.map(|o| format!("{}: {}", o.name, o.value))
|
||||||
|
.collect::<Vec<_>>()
|
||||||
|
.join(", ");
|
||||||
|
format!("/{} {}", command_name, opt_str)
|
||||||
|
} else {
|
||||||
|
format!("/{}", command_name)
|
||||||
|
};
|
||||||
|
|
||||||
|
let metadata = DiscordMessageMetadata {
|
||||||
|
channel_id: channel_id.clone(),
|
||||||
|
interaction_id: interaction.id.clone(),
|
||||||
|
token: interaction.token.clone(),
|
||||||
|
application_id: interaction.application_id.clone(),
|
||||||
|
thread_id: None,
|
||||||
|
};
|
||||||
|
|
||||||
|
let metadata_json = match serde_json::to_string(&metadata) {
|
||||||
|
Ok(json) => json,
|
||||||
|
Err(e) => {
|
||||||
|
channel_host::log(
|
||||||
|
channel_host::LogLevel::Error,
|
||||||
|
&format!("Failed to serialize metadata: {}", e),
|
||||||
|
);
|
||||||
|
// Attempt to notify user of internal error
|
||||||
|
let url = format!(
|
||||||
|
"https://discord.com/api/v10/webhooks/{}/{}",
|
||||||
|
interaction.application_id, interaction.token
|
||||||
|
);
|
||||||
|
let payload = serde_json::json!({
|
||||||
|
"content": "❌ Internal Error: Failed to process command metadata.",
|
||||||
|
"flags": 64 // Ephemeral
|
||||||
|
});
|
||||||
|
let _ = channel_host::http_request(
|
||||||
|
"POST",
|
||||||
|
&url,
|
||||||
|
&serde_json::json!({"Content-Type": "application/json"}).to_string(),
|
||||||
|
Some(&serde_json::to_vec(&payload).unwrap_or_default()),
|
||||||
|
None,
|
||||||
|
);
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
|
channel_host::emit_message(&EmittedMessage {
|
||||||
|
user_id,
|
||||||
|
user_name: Some(user_name),
|
||||||
|
content,
|
||||||
|
thread_id: None,
|
||||||
|
metadata_json,
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
fn handle_message_component(interaction: &DiscordInteraction, message: &DiscordMessage) {
|
||||||
|
// Check member first (for server contexts), then user (for DMs)
|
||||||
|
let user = interaction
|
||||||
|
.member
|
||||||
|
.as_ref()
|
||||||
|
.map(|m| &m.user)
|
||||||
|
.or(interaction.user.as_ref());
|
||||||
|
let user_id = user.map(|u| u.id.clone()).unwrap_or_default();
|
||||||
|
let user_name = user
|
||||||
|
.map(|u| {
|
||||||
|
u.global_name
|
||||||
|
.as_ref()
|
||||||
|
.filter(|s| !s.is_empty())
|
||||||
|
.unwrap_or(&u.username)
|
||||||
|
.clone()
|
||||||
|
})
|
||||||
|
.unwrap_or_default();
|
||||||
|
|
||||||
|
let channel_id = message.channel_id.clone();
|
||||||
|
|
||||||
|
let metadata = DiscordMessageMetadata {
|
||||||
|
channel_id: channel_id.clone(),
|
||||||
|
interaction_id: interaction.id.clone(),
|
||||||
|
token: interaction.token.clone(),
|
||||||
|
application_id: interaction.application_id.clone(),
|
||||||
|
thread_id: None,
|
||||||
|
};
|
||||||
|
|
||||||
|
let metadata_json = match serde_json::to_string(&metadata) {
|
||||||
|
Ok(json) => json,
|
||||||
|
Err(e) => {
|
||||||
|
channel_host::log(
|
||||||
|
channel_host::LogLevel::Error,
|
||||||
|
&format!("Failed to serialize metadata: {}", e),
|
||||||
|
);
|
||||||
|
return; // Don't emit message if metadata can't be serialized
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
|
channel_host::emit_message(&EmittedMessage {
|
||||||
|
user_id,
|
||||||
|
user_name: Some(user_name),
|
||||||
|
content: format!("[Button clicked] {}", message.content),
|
||||||
|
thread_id: None,
|
||||||
|
metadata_json,
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
fn json_response(status: u16, value: serde_json::Value) -> OutgoingHttpResponse {
|
||||||
|
let body = serde_json::to_vec(&value).unwrap_or_default();
|
||||||
|
let headers = serde_json::json!({"Content-Type": "application/json"});
|
||||||
|
|
||||||
|
OutgoingHttpResponse {
|
||||||
|
status,
|
||||||
|
headers_json: headers.to_string(),
|
||||||
|
body,
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
export!(DiscordChannel);
|
||||||
|
|
||||||
|
fn truncate_message(content: &str) -> String {
|
||||||
|
if content.len() <= 2000 {
|
||||||
|
content.to_string()
|
||||||
|
} else {
|
||||||
|
let max_bytes = 1990;
|
||||||
|
let cutoff = content
|
||||||
|
.char_indices()
|
||||||
|
.map(|(i, c)| i + c.len_utf8())
|
||||||
|
.take_while(|&end| end <= max_bytes)
|
||||||
|
.last()
|
||||||
|
.unwrap_or(0);
|
||||||
|
let mut truncated = content[..cutoff].to_string();
|
||||||
|
truncated.push_str("\n... (truncated)");
|
||||||
|
truncated
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
#[cfg(test)]
|
||||||
|
mod tests {
|
||||||
|
use super::*;
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_truncate_message() {
|
||||||
|
let short = "Hello world";
|
||||||
|
assert_eq!(truncate_message(short), short);
|
||||||
|
|
||||||
|
let long = "a".repeat(2005);
|
||||||
|
let truncated = truncate_message(&long);
|
||||||
|
assert_eq!(truncated.len(), 2006); // 1990 + 16 chars suffix
|
||||||
|
assert!(truncated.ends_with("\n... (truncated)"));
|
||||||
|
|
||||||
|
// Test with multibyte characters (Euro sign is 3 bytes)
|
||||||
|
// 1000 chars * 3 bytes = 3000 bytes
|
||||||
|
let multi = "€".repeat(1000);
|
||||||
|
let truncated_multi = truncate_message(&multi);
|
||||||
|
|
||||||
|
// 1990 bytes limit. 1990 / 3 = 663 with remainder 1.
|
||||||
|
// Should truncate at 663 chars (1989 bytes).
|
||||||
|
// Suffix is 16 bytes. Total: 1989 + 16 = 2005 bytes.
|
||||||
|
assert!(truncated_multi.len() <= 2006);
|
||||||
|
assert!(truncated_multi.len() >= 2006 - 4); // Allow for max utf8 char width variance
|
||||||
|
assert!(truncated_multi.ends_with("\n... (truncated)"));
|
||||||
|
|
||||||
|
let content_part = &truncated_multi[..truncated_multi.len() - 16];
|
||||||
|
assert!(content_part.chars().all(|c| c == '€'));
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_metadata_serialization() {
|
||||||
|
let metadata = DiscordMessageMetadata {
|
||||||
|
channel_id: "123".into(),
|
||||||
|
interaction_id: "456".into(),
|
||||||
|
token: "abc".into(),
|
||||||
|
application_id: "789".into(),
|
||||||
|
thread_id: None,
|
||||||
|
};
|
||||||
|
let json = serde_json::to_string(&metadata).unwrap();
|
||||||
|
let parsed: DiscordMessageMetadata = serde_json::from_str(&json).unwrap();
|
||||||
|
assert_eq!(parsed.channel_id, "123");
|
||||||
|
assert_eq!(parsed.interaction_id, "456");
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -30,7 +30,7 @@ if [ -f "$WASM_PATH" ]; then
|
|||||||
wasm-tools strip slack.wasm -o slack.wasm
|
wasm-tools strip slack.wasm -o slack.wasm
|
||||||
|
|
||||||
echo "Built: slack.wasm ($(du -h slack.wasm | cut -f1))"
|
echo "Built: slack.wasm ($(du -h slack.wasm | cut -f1))"
|
||||||
echo "Copy slack.wasm and slack.capabilities.json to ~/.near-agent/channels/"
|
echo "Copy slack.wasm and slack.capabilities.json to ~/.ironclaw/channels/"
|
||||||
else
|
else
|
||||||
echo "Error: WASM output not found at $WASM_PATH"
|
echo "Error: WASM output not found at $WASM_PATH"
|
||||||
exit 1
|
exit 1
|
||||||
|
|||||||
@@ -108,7 +108,10 @@ struct SlackPostMessageResponse {
|
|||||||
#[derive(Debug, Deserialize)]
|
#[derive(Debug, Deserialize)]
|
||||||
struct SlackConfig {
|
struct SlackConfig {
|
||||||
/// Name of secret containing signing secret (for verification by host).
|
/// Name of secret containing signing secret (for verification by host).
|
||||||
|
/// Parsed from config for forward compatibility; not yet used in WASM
|
||||||
|
/// (host handles signature verification).
|
||||||
#[serde(default = "default_signing_secret_name")]
|
#[serde(default = "default_signing_secret_name")]
|
||||||
|
#[allow(dead_code)]
|
||||||
signing_secret_name: String,
|
signing_secret_name: String,
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -175,11 +178,7 @@ impl Guest for SlackChannel {
|
|||||||
// Actual event callback
|
// Actual event callback
|
||||||
"event_callback" => {
|
"event_callback" => {
|
||||||
if let Some(event) = event_wrapper.event {
|
if let Some(event) = event_wrapper.event {
|
||||||
handle_slack_event(
|
handle_slack_event(event, event_wrapper.team_id, event_wrapper.event_id);
|
||||||
event,
|
|
||||||
event_wrapper.team_id,
|
|
||||||
event_wrapper.event_id,
|
|
||||||
);
|
|
||||||
}
|
}
|
||||||
// Always respond 200 quickly to Slack (they have a 3s timeout)
|
// Always respond 200 quickly to Slack (they have a 3s timeout)
|
||||||
json_response(200, serde_json::json!({"ok": true}))
|
json_response(200, serde_json::json!({"ok": true}))
|
||||||
@@ -230,6 +229,7 @@ impl Guest for SlackChannel {
|
|||||||
"https://slack.com/api/chat.postMessage",
|
"https://slack.com/api/chat.postMessage",
|
||||||
&headers.to_string(),
|
&headers.to_string(),
|
||||||
Some(&payload_bytes),
|
Some(&payload_bytes),
|
||||||
|
None,
|
||||||
);
|
);
|
||||||
|
|
||||||
match result {
|
match result {
|
||||||
@@ -243,14 +243,15 @@ impl Guest for SlackChannel {
|
|||||||
|
|
||||||
// Parse Slack response
|
// Parse Slack response
|
||||||
let slack_response: SlackPostMessageResponse =
|
let slack_response: SlackPostMessageResponse =
|
||||||
serde_json::from_slice(&http_response.body).map_err(|e| {
|
serde_json::from_slice(&http_response.body)
|
||||||
format!("Failed to parse Slack response: {}", e)
|
.map_err(|e| format!("Failed to parse Slack response: {}", e))?;
|
||||||
})?;
|
|
||||||
|
|
||||||
if !slack_response.ok {
|
if !slack_response.ok {
|
||||||
return Err(format!(
|
return Err(format!(
|
||||||
"Slack API error: {}",
|
"Slack API error: {}",
|
||||||
slack_response.error.unwrap_or_else(|| "unknown".to_string())
|
slack_response
|
||||||
|
.error
|
||||||
|
.unwrap_or_else(|| "unknown".to_string())
|
||||||
));
|
));
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -277,17 +278,16 @@ impl Guest for SlackChannel {
|
|||||||
}
|
}
|
||||||
|
|
||||||
/// Handle a Slack event and emit message if applicable.
|
/// Handle a Slack event and emit message if applicable.
|
||||||
fn handle_slack_event(
|
fn handle_slack_event(event: SlackEvent, team_id: Option<String>, _event_id: Option<String>) {
|
||||||
event: SlackEvent,
|
|
||||||
team_id: Option<String>,
|
|
||||||
_event_id: Option<String>,
|
|
||||||
) {
|
|
||||||
match event.event_type.as_str() {
|
match event.event_type.as_str() {
|
||||||
// Direct mention of the bot
|
// Direct mention of the bot
|
||||||
"app_mention" => {
|
"app_mention" => {
|
||||||
if let (Some(user), Some(channel), Some(text), Some(ts)) =
|
if let (Some(user), Some(channel), Some(text), Some(ts)) = (
|
||||||
(event.user, event.channel.clone(), event.text, event.ts.clone())
|
event.user,
|
||||||
{
|
event.channel.clone(),
|
||||||
|
event.text,
|
||||||
|
event.ts.clone(),
|
||||||
|
) {
|
||||||
emit_message(user, text, channel, event.thread_ts.or(Some(ts)), team_id);
|
emit_message(user, text, channel, event.thread_ts.or(Some(ts)), team_id);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -299,9 +299,12 @@ fn handle_slack_event(
|
|||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
|
||||||
if let (Some(user), Some(channel), Some(text), Some(ts)) =
|
if let (Some(user), Some(channel), Some(text), Some(ts)) = (
|
||||||
(event.user, event.channel.clone(), event.text, event.ts.clone())
|
event.user,
|
||||||
{
|
event.channel.clone(),
|
||||||
|
event.text,
|
||||||
|
event.ts.clone(),
|
||||||
|
) {
|
||||||
// Only process DMs (channel IDs starting with D)
|
// Only process DMs (channel IDs starting with D)
|
||||||
if channel.starts_with('D') {
|
if channel.starts_with('D') {
|
||||||
emit_message(user, text, channel, event.thread_ts.or(Some(ts)), team_id);
|
emit_message(user, text, channel, event.thread_ts.or(Some(ts)), team_id);
|
||||||
@@ -335,8 +338,13 @@ fn emit_message(
|
|||||||
team_id,
|
team_id,
|
||||||
};
|
};
|
||||||
|
|
||||||
let metadata_json =
|
let metadata_json = serde_json::to_string(&metadata).unwrap_or_else(|e| {
|
||||||
serde_json::to_string(&metadata).unwrap_or_else(|_| "{}".to_string());
|
channel_host::log(
|
||||||
|
channel_host::LogLevel::Error,
|
||||||
|
&format!("Failed to serialize Slack metadata: {}", e),
|
||||||
|
);
|
||||||
|
"{}".to_string()
|
||||||
|
});
|
||||||
|
|
||||||
// Strip @ mentions of the bot from the text for cleaner messages
|
// Strip @ mentions of the bot from the text for cleaner messages
|
||||||
let cleaned_text = strip_bot_mention(&text);
|
let cleaned_text = strip_bot_mention(&text);
|
||||||
@@ -364,7 +372,13 @@ fn strip_bot_mention(text: &str) -> String {
|
|||||||
|
|
||||||
/// Create a JSON HTTP response.
|
/// Create a JSON HTTP response.
|
||||||
fn json_response(status: u16, value: serde_json::Value) -> OutgoingHttpResponse {
|
fn json_response(status: u16, value: serde_json::Value) -> OutgoingHttpResponse {
|
||||||
let body = serde_json::to_vec(&value).unwrap_or_default();
|
let body = serde_json::to_vec(&value).unwrap_or_else(|e| {
|
||||||
|
channel_host::log(
|
||||||
|
channel_host::LogLevel::Error,
|
||||||
|
&format!("Failed to serialize JSON response: {}", e),
|
||||||
|
);
|
||||||
|
Vec::new()
|
||||||
|
});
|
||||||
let headers = serde_json::json!({"Content-Type": "application/json"});
|
let headers = serde_json::json!({"Content-Type": "application/json"});
|
||||||
|
|
||||||
OutgoingHttpResponse {
|
OutgoingHttpResponse {
|
||||||
|
|||||||
@@ -32,8 +32,8 @@ if [ -f "$WASM_PATH" ]; then
|
|||||||
echo "Built: telegram.wasm ($(du -h telegram.wasm | cut -f1))"
|
echo "Built: telegram.wasm ($(du -h telegram.wasm | cut -f1))"
|
||||||
echo ""
|
echo ""
|
||||||
echo "To install:"
|
echo "To install:"
|
||||||
echo " mkdir -p ~/.near-agent/channels"
|
echo " mkdir -p ~/.ironclaw/channels"
|
||||||
echo " cp telegram.wasm telegram.capabilities.json ~/.near-agent/channels/"
|
echo " cp telegram.wasm telegram.capabilities.json ~/.ironclaw/channels/"
|
||||||
echo ""
|
echo ""
|
||||||
echo "Then add your bot token to secrets:"
|
echo "Then add your bot token to secrets:"
|
||||||
echo " # Set TELEGRAM_BOT_TOKEN in your environment or secrets store"
|
echo " # Set TELEGRAM_BOT_TOKEN in your environment or secrets store"
|
||||||
|
|||||||
@@ -72,6 +72,10 @@ struct TelegramMessage {
|
|||||||
/// Message text.
|
/// Message text.
|
||||||
text: Option<String>,
|
text: Option<String>,
|
||||||
|
|
||||||
|
/// Caption for media (photo, video, document, etc.).
|
||||||
|
#[serde(default)]
|
||||||
|
caption: Option<String>,
|
||||||
|
|
||||||
/// Original message if this is a reply.
|
/// Original message if this is a reply.
|
||||||
reply_to_message: Option<Box<TelegramMessage>>,
|
reply_to_message: Option<Box<TelegramMessage>>,
|
||||||
|
|
||||||
@@ -160,6 +164,21 @@ const POLLING_STATE_PATH: &str = "state/last_update_id";
|
|||||||
/// Workspace path for persisting owner_id across WASM callbacks.
|
/// Workspace path for persisting owner_id across WASM callbacks.
|
||||||
const OWNER_ID_PATH: &str = "state/owner_id";
|
const OWNER_ID_PATH: &str = "state/owner_id";
|
||||||
|
|
||||||
|
/// Workspace path for persisting dm_policy across WASM callbacks.
|
||||||
|
const DM_POLICY_PATH: &str = "state/dm_policy";
|
||||||
|
|
||||||
|
/// Workspace path for persisting allow_from (JSON array) across WASM callbacks.
|
||||||
|
const ALLOW_FROM_PATH: &str = "state/allow_from";
|
||||||
|
|
||||||
|
/// Channel name for pairing store (used by pairing host APIs).
|
||||||
|
const CHANNEL_NAME: &str = "telegram";
|
||||||
|
|
||||||
|
/// Workspace path for persisting bot_username for mention detection in groups.
|
||||||
|
const BOT_USERNAME_PATH: &str = "state/bot_username";
|
||||||
|
|
||||||
|
/// Workspace path for persisting respond_to_all_group_messages flag.
|
||||||
|
const RESPOND_TO_ALL_GROUP_PATH: &str = "state/respond_to_all_group_messages";
|
||||||
|
|
||||||
// ============================================================================
|
// ============================================================================
|
||||||
// Channel Metadata
|
// Channel Metadata
|
||||||
// ============================================================================
|
// ============================================================================
|
||||||
@@ -196,6 +215,14 @@ struct TelegramConfig {
|
|||||||
#[serde(default)]
|
#[serde(default)]
|
||||||
owner_id: Option<i64>,
|
owner_id: Option<i64>,
|
||||||
|
|
||||||
|
/// DM policy: "pairing" (default), "allowlist", or "open".
|
||||||
|
#[serde(default)]
|
||||||
|
dm_policy: Option<String>,
|
||||||
|
|
||||||
|
/// Allowed sender IDs/usernames from config (merged with pairing-approved store).
|
||||||
|
#[serde(default)]
|
||||||
|
allow_from: Option<Vec<String>>,
|
||||||
|
|
||||||
/// Whether to respond to all group messages (not just mentions).
|
/// Whether to respond to all group messages (not just mentions).
|
||||||
#[serde(default)]
|
#[serde(default)]
|
||||||
respond_to_all_group_messages: bool,
|
respond_to_all_group_messages: bool,
|
||||||
@@ -257,6 +284,24 @@ impl Guest for TelegramChannel {
|
|||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Persist dm_policy and allow_from for DM pairing in handle_message
|
||||||
|
let dm_policy = config.dm_policy.as_deref().unwrap_or("pairing").to_string();
|
||||||
|
let _ = channel_host::workspace_write(DM_POLICY_PATH, &dm_policy);
|
||||||
|
|
||||||
|
let allow_from_json = serde_json::to_string(&config.allow_from.unwrap_or_default())
|
||||||
|
.unwrap_or_else(|_| "[]".to_string());
|
||||||
|
let _ = channel_host::workspace_write(ALLOW_FROM_PATH, &allow_from_json);
|
||||||
|
|
||||||
|
// Persist bot_username and respond_to_all_group_messages for group handling
|
||||||
|
let _ = channel_host::workspace_write(
|
||||||
|
BOT_USERNAME_PATH,
|
||||||
|
&config.bot_username.unwrap_or_default(),
|
||||||
|
);
|
||||||
|
let _ = channel_host::workspace_write(
|
||||||
|
RESPOND_TO_ALL_GROUP_PATH,
|
||||||
|
&config.respond_to_all_group_messages.to_string(),
|
||||||
|
);
|
||||||
|
|
||||||
// Mode is determined by whether the host injected a tunnel_url
|
// Mode is determined by whether the host injected a tunnel_url
|
||||||
// If tunnel is configured, use webhooks. Otherwise, use polling.
|
// If tunnel is configured, use webhooks. Otherwise, use polling.
|
||||||
let webhook_mode = config.tunnel_url.is_some();
|
let webhook_mode = config.tunnel_url.is_some();
|
||||||
@@ -388,7 +433,9 @@ impl Guest for TelegramChannel {
|
|||||||
|
|
||||||
let headers = serde_json::json!({});
|
let headers = serde_json::json!({});
|
||||||
|
|
||||||
let result = channel_host::http_request("GET", &url, &headers.to_string(), None);
|
// 35s HTTP timeout outlives Telegram's 30s server-side long-poll
|
||||||
|
let result =
|
||||||
|
channel_host::http_request("GET", &url, &headers.to_string(), None, Some(35_000));
|
||||||
|
|
||||||
match result {
|
match result {
|
||||||
Ok(response) => {
|
Ok(response) => {
|
||||||
@@ -461,72 +508,52 @@ impl Guest for TelegramChannel {
|
|||||||
}
|
}
|
||||||
|
|
||||||
fn on_respond(response: AgentResponse) -> Result<(), String> {
|
fn on_respond(response: AgentResponse) -> Result<(), String> {
|
||||||
// Parse metadata to get chat info
|
|
||||||
let metadata: TelegramMessageMetadata = serde_json::from_str(&response.metadata_json)
|
let metadata: TelegramMessageMetadata = serde_json::from_str(&response.metadata_json)
|
||||||
.map_err(|e| format!("Failed to parse metadata: {}", e))?;
|
.map_err(|e| format!("Failed to parse metadata: {}", e))?;
|
||||||
|
|
||||||
// Build sendMessage payload
|
// Try sending with Markdown first; fall back to plain text if Telegram
|
||||||
let mut payload = serde_json::json!({
|
// can't parse the entities (e.g. model leaked <tool_call> with underscores).
|
||||||
"chat_id": metadata.chat_id,
|
let result = send_message(
|
||||||
"text": response.content,
|
metadata.chat_id,
|
||||||
"parse_mode": "Markdown",
|
&response.content,
|
||||||
});
|
metadata.message_id,
|
||||||
|
Some("Markdown"),
|
||||||
// Reply to the original message for context
|
|
||||||
payload["reply_to_message_id"] = serde_json::Value::Number(metadata.message_id.into());
|
|
||||||
|
|
||||||
let payload_bytes = serde_json::to_vec(&payload)
|
|
||||||
.map_err(|e| format!("Failed to serialize payload: {}", e))?;
|
|
||||||
|
|
||||||
// Make HTTP request to Telegram API
|
|
||||||
// The bot token is injected into the URL by the host
|
|
||||||
let headers = serde_json::json!({
|
|
||||||
"Content-Type": "application/json"
|
|
||||||
});
|
|
||||||
|
|
||||||
let result = channel_host::http_request(
|
|
||||||
"POST",
|
|
||||||
"https://api.telegram.org/bot{TELEGRAM_BOT_TOKEN}/sendMessage",
|
|
||||||
&headers.to_string(),
|
|
||||||
Some(&payload_bytes),
|
|
||||||
);
|
);
|
||||||
|
|
||||||
match result {
|
match result {
|
||||||
Ok(http_response) => {
|
Ok(msg_id) => {
|
||||||
if http_response.status != 200 {
|
|
||||||
let body_str = String::from_utf8_lossy(&http_response.body);
|
|
||||||
return Err(format!(
|
|
||||||
"Telegram API returned status {}: {}",
|
|
||||||
http_response.status, body_str
|
|
||||||
));
|
|
||||||
}
|
|
||||||
|
|
||||||
// Parse Telegram response
|
|
||||||
let api_response: TelegramApiResponse<SentMessage> =
|
|
||||||
serde_json::from_slice(&http_response.body)
|
|
||||||
.map_err(|e| format!("Failed to parse Telegram response: {}", e))?;
|
|
||||||
|
|
||||||
if !api_response.ok {
|
|
||||||
return Err(format!(
|
|
||||||
"Telegram API error: {}",
|
|
||||||
api_response
|
|
||||||
.description
|
|
||||||
.unwrap_or_else(|| "unknown".to_string())
|
|
||||||
));
|
|
||||||
}
|
|
||||||
|
|
||||||
channel_host::log(
|
channel_host::log(
|
||||||
channel_host::LogLevel::Debug,
|
channel_host::LogLevel::Debug,
|
||||||
&format!(
|
&format!(
|
||||||
"Sent message to chat {}: message_id={}",
|
"Sent message to chat {}: message_id={}",
|
||||||
metadata.chat_id,
|
metadata.chat_id, msg_id
|
||||||
api_response.result.map(|r| r.message_id).unwrap_or(0)
|
|
||||||
),
|
),
|
||||||
);
|
);
|
||||||
|
|
||||||
Ok(())
|
Ok(())
|
||||||
}
|
}
|
||||||
Err(e) => Err(format!("HTTP request failed: {}", e)),
|
Err(SendError::ParseEntities(detail)) => {
|
||||||
|
channel_host::log(
|
||||||
|
channel_host::LogLevel::Warn,
|
||||||
|
&format!("Markdown parse failed ({}), retrying as plain text", detail),
|
||||||
|
);
|
||||||
|
let msg_id = send_message(
|
||||||
|
metadata.chat_id,
|
||||||
|
&response.content,
|
||||||
|
metadata.message_id,
|
||||||
|
None,
|
||||||
|
)
|
||||||
|
.map_err(|e| format!("Plain-text retry also failed: {}", e))?;
|
||||||
|
|
||||||
|
channel_host::log(
|
||||||
|
channel_host::LogLevel::Debug,
|
||||||
|
&format!(
|
||||||
|
"Sent plain-text message to chat {}: message_id={}",
|
||||||
|
metadata.chat_id, msg_id
|
||||||
|
),
|
||||||
|
);
|
||||||
|
Ok(())
|
||||||
|
}
|
||||||
|
Err(e) => Err(e.to_string()),
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -568,6 +595,7 @@ impl Guest for TelegramChannel {
|
|||||||
"https://api.telegram.org/bot{TELEGRAM_BOT_TOKEN}/sendChatAction",
|
"https://api.telegram.org/bot{TELEGRAM_BOT_TOKEN}/sendChatAction",
|
||||||
&headers.to_string(),
|
&headers.to_string(),
|
||||||
Some(&payload_bytes),
|
Some(&payload_bytes),
|
||||||
|
None,
|
||||||
);
|
);
|
||||||
|
|
||||||
if let Err(e) = result {
|
if let Err(e) = result {
|
||||||
@@ -586,6 +614,101 @@ impl Guest for TelegramChannel {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// ============================================================================
|
||||||
|
// Send Message Helper
|
||||||
|
// ============================================================================
|
||||||
|
|
||||||
|
/// Errors from send_message, split so callers can match on parse-entity failures.
|
||||||
|
enum SendError {
|
||||||
|
/// Telegram returned 400 with "can't parse entities" (Markdown issue).
|
||||||
|
ParseEntities(String),
|
||||||
|
/// Any other failure.
|
||||||
|
Other(String),
|
||||||
|
}
|
||||||
|
|
||||||
|
impl std::fmt::Display for SendError {
|
||||||
|
fn fmt(&self, f: &mut std::fmt::Formatter<'_>) -> std::fmt::Result {
|
||||||
|
match self {
|
||||||
|
SendError::ParseEntities(detail) => write!(f, "parse entities error: {}", detail),
|
||||||
|
SendError::Other(msg) => write!(f, "{}", msg),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Send a message via the Telegram Bot API.
|
||||||
|
///
|
||||||
|
/// Returns the sent message_id on success. When `parse_mode` is set and
|
||||||
|
/// Telegram returns a 400 "can't parse entities" error, returns
|
||||||
|
/// `SendError::ParseEntities` so the caller can retry without formatting.
|
||||||
|
fn send_message(
|
||||||
|
chat_id: i64,
|
||||||
|
text: &str,
|
||||||
|
reply_to_message_id: i64,
|
||||||
|
parse_mode: Option<&str>,
|
||||||
|
) -> Result<i64, SendError> {
|
||||||
|
let mut payload = serde_json::json!({
|
||||||
|
"chat_id": chat_id,
|
||||||
|
"text": text,
|
||||||
|
"reply_to_message_id": reply_to_message_id,
|
||||||
|
});
|
||||||
|
|
||||||
|
if let Some(mode) = parse_mode {
|
||||||
|
payload["parse_mode"] = serde_json::Value::String(mode.to_string());
|
||||||
|
}
|
||||||
|
|
||||||
|
let payload_bytes = serde_json::to_vec(&payload)
|
||||||
|
.map_err(|e| SendError::Other(format!("Failed to serialize payload: {}", e)))?;
|
||||||
|
|
||||||
|
let headers = serde_json::json!({ "Content-Type": "application/json" });
|
||||||
|
|
||||||
|
let result = channel_host::http_request(
|
||||||
|
"POST",
|
||||||
|
"https://api.telegram.org/bot{TELEGRAM_BOT_TOKEN}/sendMessage",
|
||||||
|
&headers.to_string(),
|
||||||
|
Some(&payload_bytes),
|
||||||
|
None,
|
||||||
|
);
|
||||||
|
|
||||||
|
match result {
|
||||||
|
Ok(http_response) => {
|
||||||
|
if http_response.status == 400 {
|
||||||
|
let body_str = String::from_utf8_lossy(&http_response.body);
|
||||||
|
if body_str.contains("can't parse entities") {
|
||||||
|
return Err(SendError::ParseEntities(body_str.to_string()));
|
||||||
|
}
|
||||||
|
return Err(SendError::Other(format!(
|
||||||
|
"Telegram API returned 400: {}",
|
||||||
|
body_str
|
||||||
|
)));
|
||||||
|
}
|
||||||
|
|
||||||
|
if http_response.status != 200 {
|
||||||
|
let body_str = String::from_utf8_lossy(&http_response.body);
|
||||||
|
return Err(SendError::Other(format!(
|
||||||
|
"Telegram API returned status {}: {}",
|
||||||
|
http_response.status, body_str
|
||||||
|
)));
|
||||||
|
}
|
||||||
|
|
||||||
|
let api_response: TelegramApiResponse<SentMessage> =
|
||||||
|
serde_json::from_slice(&http_response.body)
|
||||||
|
.map_err(|e| SendError::Other(format!("Failed to parse response: {}", e)))?;
|
||||||
|
|
||||||
|
if !api_response.ok {
|
||||||
|
return Err(SendError::Other(format!(
|
||||||
|
"Telegram API error: {}",
|
||||||
|
api_response
|
||||||
|
.description
|
||||||
|
.unwrap_or_else(|| "unknown".to_string())
|
||||||
|
)));
|
||||||
|
}
|
||||||
|
|
||||||
|
Ok(api_response.result.map(|r| r.message_id).unwrap_or(0))
|
||||||
|
}
|
||||||
|
Err(e) => Err(SendError::Other(format!("HTTP request failed: {}", e))),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
// ============================================================================
|
// ============================================================================
|
||||||
// Webhook Management
|
// Webhook Management
|
||||||
// ============================================================================
|
// ============================================================================
|
||||||
@@ -604,6 +727,7 @@ fn delete_webhook() -> Result<(), String> {
|
|||||||
"https://api.telegram.org/bot{TELEGRAM_BOT_TOKEN}/deleteWebhook",
|
"https://api.telegram.org/bot{TELEGRAM_BOT_TOKEN}/deleteWebhook",
|
||||||
&headers.to_string(),
|
&headers.to_string(),
|
||||||
None,
|
None,
|
||||||
|
None,
|
||||||
);
|
);
|
||||||
|
|
||||||
match result {
|
match result {
|
||||||
@@ -666,6 +790,7 @@ fn register_webhook(tunnel_url: &str, webhook_secret: Option<&str>) -> Result<()
|
|||||||
"https://api.telegram.org/bot{TELEGRAM_BOT_TOKEN}/setWebhook",
|
"https://api.telegram.org/bot{TELEGRAM_BOT_TOKEN}/setWebhook",
|
||||||
&headers.to_string(),
|
&headers.to_string(),
|
||||||
Some(&body_bytes),
|
Some(&body_bytes),
|
||||||
|
None,
|
||||||
);
|
);
|
||||||
|
|
||||||
match result {
|
match result {
|
||||||
@@ -700,6 +825,48 @@ fn register_webhook(tunnel_url: &str, webhook_secret: Option<&str>) -> Result<()
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// ============================================================================
|
||||||
|
// Pairing Reply
|
||||||
|
// ============================================================================
|
||||||
|
|
||||||
|
/// Send a pairing code message to a chat. Used when an unknown user DMs the bot.
|
||||||
|
fn send_pairing_reply(chat_id: i64, code: &str) -> Result<(), String> {
|
||||||
|
let payload = serde_json::json!({
|
||||||
|
"chat_id": chat_id,
|
||||||
|
"text": format!(
|
||||||
|
"To pair with this bot, run: `ironclaw pairing approve telegram {}`",
|
||||||
|
code
|
||||||
|
),
|
||||||
|
"parse_mode": "Markdown",
|
||||||
|
});
|
||||||
|
|
||||||
|
let payload_bytes =
|
||||||
|
serde_json::to_vec(&payload).map_err(|e| format!("Failed to serialize payload: {}", e))?;
|
||||||
|
|
||||||
|
let headers = serde_json::json!({
|
||||||
|
"Content-Type": "application/json"
|
||||||
|
});
|
||||||
|
|
||||||
|
let result = channel_host::http_request(
|
||||||
|
"POST",
|
||||||
|
"https://api.telegram.org/bot{TELEGRAM_BOT_TOKEN}/sendMessage",
|
||||||
|
&headers.to_string(),
|
||||||
|
Some(&payload_bytes),
|
||||||
|
None,
|
||||||
|
);
|
||||||
|
|
||||||
|
match result {
|
||||||
|
Ok(response) => {
|
||||||
|
if response.status != 200 {
|
||||||
|
let body_str = String::from_utf8_lossy(&response.body);
|
||||||
|
return Err(format!("HTTP {}: {}", response.status, body_str));
|
||||||
|
}
|
||||||
|
Ok(())
|
||||||
|
}
|
||||||
|
Err(e) => Err(format!("HTTP request failed: {}", e)),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
// ============================================================================
|
// ============================================================================
|
||||||
// Update Handling
|
// Update Handling
|
||||||
// ============================================================================
|
// ============================================================================
|
||||||
@@ -719,11 +886,16 @@ fn handle_update(update: TelegramUpdate) {
|
|||||||
|
|
||||||
/// Process a single message.
|
/// Process a single message.
|
||||||
fn handle_message(message: TelegramMessage) {
|
fn handle_message(message: TelegramMessage) {
|
||||||
// Skip messages without text
|
// Use text or caption (for media messages)
|
||||||
let text = match message.text {
|
let content = message
|
||||||
Some(t) if !t.is_empty() => t,
|
.text
|
||||||
_ => return,
|
.filter(|t| !t.is_empty())
|
||||||
};
|
.or_else(|| message.caption.filter(|c| !c.is_empty()))
|
||||||
|
.unwrap_or_default();
|
||||||
|
|
||||||
|
if content.is_empty() {
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
// Skip messages without a sender (channel posts)
|
// Skip messages without a sender (channel posts)
|
||||||
let from = match message.from {
|
let from = match message.from {
|
||||||
@@ -736,10 +908,13 @@ fn handle_message(message: TelegramMessage) {
|
|||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
|
||||||
// Owner validation: silently drop messages from non-owner users
|
let is_private = message.chat.chat_type == "private";
|
||||||
if let Some(owner_id_str) = channel_host::workspace_read(OWNER_ID_PATH) {
|
|
||||||
if !owner_id_str.is_empty() {
|
// Owner validation: when owner_id is set, only that user can message
|
||||||
if let Ok(owner_id) = owner_id_str.parse::<i64>() {
|
let owner_id_str = channel_host::workspace_read(OWNER_ID_PATH).filter(|s| !s.is_empty());
|
||||||
|
|
||||||
|
if let Some(ref id_str) = owner_id_str {
|
||||||
|
if let Ok(owner_id) = id_str.parse::<i64>() {
|
||||||
if from.id != owner_id {
|
if from.id != owner_id {
|
||||||
channel_host::log(
|
channel_host::log(
|
||||||
channel_host::LogLevel::Debug,
|
channel_host::LogLevel::Debug,
|
||||||
@@ -751,28 +926,89 @@ fn handle_message(message: TelegramMessage) {
|
|||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
} else if is_private {
|
||||||
|
// No owner_id: apply dm_policy for private chats
|
||||||
|
let dm_policy =
|
||||||
|
channel_host::workspace_read(DM_POLICY_PATH).unwrap_or_else(|| "pairing".to_string());
|
||||||
|
|
||||||
|
if dm_policy != "open" {
|
||||||
|
// Build effective allow list: config allow_from + pairing store
|
||||||
|
let mut allowed: Vec<String> = channel_host::workspace_read(ALLOW_FROM_PATH)
|
||||||
|
.and_then(|s| serde_json::from_str(&s).ok())
|
||||||
|
.unwrap_or_default();
|
||||||
|
|
||||||
|
if let Ok(store_allowed) = channel_host::pairing_read_allow_from(CHANNEL_NAME) {
|
||||||
|
allowed.extend(store_allowed);
|
||||||
|
}
|
||||||
|
|
||||||
|
let id_str = from.id.to_string();
|
||||||
|
let username_opt = from.username.as_deref();
|
||||||
|
let is_allowed = allowed.contains(&"*".to_string())
|
||||||
|
|| allowed.contains(&id_str)
|
||||||
|
|| username_opt.map_or(false, |u| allowed.contains(&u.to_string()));
|
||||||
|
|
||||||
|
if !is_allowed {
|
||||||
|
if dm_policy == "pairing" {
|
||||||
|
// Upsert pairing request and send reply
|
||||||
|
let meta = serde_json::json!({
|
||||||
|
"chat_id": message.chat.id,
|
||||||
|
"user_id": from.id,
|
||||||
|
"username": username_opt,
|
||||||
|
})
|
||||||
|
.to_string();
|
||||||
|
|
||||||
|
match channel_host::pairing_upsert_request(CHANNEL_NAME, &id_str, &meta) {
|
||||||
|
Ok(result) => {
|
||||||
|
channel_host::log(
|
||||||
|
channel_host::LogLevel::Info,
|
||||||
|
&format!(
|
||||||
|
"Pairing request for user {} (chat {}): code {}",
|
||||||
|
from.id, message.chat.id, result.code
|
||||||
|
),
|
||||||
|
);
|
||||||
|
if result.created {
|
||||||
|
let _ = send_pairing_reply(message.chat.id, &result.code);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
Err(e) => {
|
||||||
|
channel_host::log(
|
||||||
|
channel_host::LogLevel::Error,
|
||||||
|
&format!("Pairing upsert failed: {}", e),
|
||||||
|
);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return;
|
||||||
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
let is_private = message.chat.chat_type == "private";
|
// For group chats, only respond if bot was mentioned or respond_to_all is enabled
|
||||||
|
|
||||||
// For group chats, check if the bot was mentioned
|
|
||||||
// TODO: Read bot_username from config and check mentions
|
|
||||||
// For now, process all messages in private chats and groups
|
|
||||||
if !is_private {
|
if !is_private {
|
||||||
// In groups, only respond if there's a bot mention or command
|
let respond_to_all = channel_host::workspace_read(RESPOND_TO_ALL_GROUP_PATH)
|
||||||
// This is a simplified check - proper implementation would use entities
|
.as_deref()
|
||||||
let has_command = text.starts_with('/');
|
.unwrap_or("false")
|
||||||
let has_mention = text.contains('@');
|
== "true";
|
||||||
|
|
||||||
if !has_command && !has_mention {
|
if !respond_to_all {
|
||||||
|
let has_command = content.starts_with('/');
|
||||||
|
let bot_username = channel_host::workspace_read(BOT_USERNAME_PATH).unwrap_or_default();
|
||||||
|
let has_bot_mention = if bot_username.is_empty() {
|
||||||
|
content.contains('@')
|
||||||
|
} else {
|
||||||
|
let mention = format!("@{}", bot_username);
|
||||||
|
content.to_lowercase().contains(&mention.to_lowercase())
|
||||||
|
};
|
||||||
|
|
||||||
|
if !has_command && !has_bot_mention {
|
||||||
channel_host::log(
|
channel_host::log(
|
||||||
channel_host::LogLevel::Debug,
|
channel_host::LogLevel::Debug,
|
||||||
&format!("Ignoring group message without mention: {}", text),
|
&format!("Ignoring group message without mention: {}", content),
|
||||||
);
|
);
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
}
|
||||||
|
|
||||||
// Build user display name
|
// Build user display name
|
||||||
let user_name = if let Some(ref last) = from.last_name {
|
let user_name = if let Some(ref last) = from.last_name {
|
||||||
@@ -792,17 +1028,30 @@ fn handle_message(message: TelegramMessage) {
|
|||||||
let metadata_json = serde_json::to_string(&metadata).unwrap_or_else(|_| "{}".to_string());
|
let metadata_json = serde_json::to_string(&metadata).unwrap_or_else(|_| "{}".to_string());
|
||||||
|
|
||||||
// Clean the message text (strip bot mentions and commands)
|
// Clean the message text (strip bot mentions and commands)
|
||||||
let cleaned_text = clean_message_text(&text);
|
let bot_username = channel_host::workspace_read(BOT_USERNAME_PATH).unwrap_or_default();
|
||||||
|
let cleaned_text = clean_message_text(
|
||||||
|
&content,
|
||||||
|
if bot_username.is_empty() {
|
||||||
|
None
|
||||||
|
} else {
|
||||||
|
Some(bot_username.as_str())
|
||||||
|
},
|
||||||
|
);
|
||||||
|
|
||||||
if cleaned_text.is_empty() {
|
// For /start with no args, emit placeholder so agent can respond with welcome
|
||||||
|
let content_to_emit = if cleaned_text.is_empty() && content.trim().starts_with('/') {
|
||||||
|
"[User started the bot]".to_string()
|
||||||
|
} else if cleaned_text.is_empty() {
|
||||||
return;
|
return;
|
||||||
}
|
} else {
|
||||||
|
cleaned_text
|
||||||
|
};
|
||||||
|
|
||||||
// Emit the message to the agent
|
// Emit the message to the agent
|
||||||
channel_host::emit_message(&EmittedMessage {
|
channel_host::emit_message(&EmittedMessage {
|
||||||
user_id: from.id.to_string(),
|
user_id: from.id.to_string(),
|
||||||
user_name: Some(user_name),
|
user_name: Some(user_name),
|
||||||
content: cleaned_text,
|
content: content_to_emit,
|
||||||
thread_id: None, // Telegram doesn't have threads in the same way
|
thread_id: None, // Telegram doesn't have threads in the same way
|
||||||
metadata_json,
|
metadata_json,
|
||||||
});
|
});
|
||||||
@@ -817,7 +1066,8 @@ fn handle_message(message: TelegramMessage) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
/// Clean message text by removing bot commands and @mentions at the start.
|
/// Clean message text by removing bot commands and @mentions at the start.
|
||||||
fn clean_message_text(text: &str) -> String {
|
/// When bot_username is set, only strips that specific mention; otherwise strips any leading @mention.
|
||||||
|
fn clean_message_text(text: &str, bot_username: Option<&str>) -> String {
|
||||||
let mut result = text.trim().to_string();
|
let mut result = text.trim().to_string();
|
||||||
|
|
||||||
// Remove leading /command
|
// Remove leading /command
|
||||||
@@ -832,13 +1082,32 @@ fn clean_message_text(text: &str) -> String {
|
|||||||
|
|
||||||
// Remove leading @mention
|
// Remove leading @mention
|
||||||
if result.starts_with('@') {
|
if result.starts_with('@') {
|
||||||
|
if let Some(bot) = bot_username {
|
||||||
|
let mention = format!("@{}", bot);
|
||||||
|
let mention_lower = mention.to_lowercase();
|
||||||
|
let result_lower = result.to_lowercase();
|
||||||
|
if result_lower.starts_with(&mention_lower) {
|
||||||
|
let rest = result[mention.len()..].trim_start();
|
||||||
|
if rest.is_empty() {
|
||||||
|
return String::new();
|
||||||
|
}
|
||||||
|
result = rest.to_string();
|
||||||
|
} else if let Some(space_idx) = result.find(' ') {
|
||||||
|
// Different leading @mention - only strip if it's the bot
|
||||||
|
let first_word = &result[..space_idx];
|
||||||
|
if first_word.eq_ignore_ascii_case(&mention) {
|
||||||
|
result = result[space_idx..].trim_start().to_string();
|
||||||
|
}
|
||||||
|
}
|
||||||
|
} else {
|
||||||
|
// No bot_username: strip any leading @mention
|
||||||
if let Some(space_idx) = result.find(' ') {
|
if let Some(space_idx) = result.find(' ') {
|
||||||
result = result[space_idx..].trim_start().to_string();
|
result = result[space_idx..].trim_start().to_string();
|
||||||
} else {
|
} else {
|
||||||
// Just a mention with no text
|
|
||||||
return String::new();
|
return String::new();
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
}
|
||||||
|
|
||||||
result
|
result
|
||||||
}
|
}
|
||||||
@@ -872,12 +1141,22 @@ mod tests {
|
|||||||
|
|
||||||
#[test]
|
#[test]
|
||||||
fn test_clean_message_text() {
|
fn test_clean_message_text() {
|
||||||
assert_eq!(clean_message_text("/start hello"), "hello");
|
// Without bot_username: strips any leading @mention
|
||||||
assert_eq!(clean_message_text("@bot hello world"), "hello world");
|
assert_eq!(clean_message_text("/start hello", None), "hello");
|
||||||
assert_eq!(clean_message_text("/start"), "");
|
assert_eq!(clean_message_text("@bot hello world", None), "hello world");
|
||||||
assert_eq!(clean_message_text("@botname"), "");
|
assert_eq!(clean_message_text("/start", None), "");
|
||||||
assert_eq!(clean_message_text("just text"), "just text");
|
assert_eq!(clean_message_text("@botname", None), "");
|
||||||
assert_eq!(clean_message_text(" spaced "), "spaced");
|
assert_eq!(clean_message_text("just text", None), "just text");
|
||||||
|
assert_eq!(clean_message_text(" spaced ", None), "spaced");
|
||||||
|
|
||||||
|
// With bot_username: only strips @MyBot, not @alice
|
||||||
|
assert_eq!(clean_message_text("@MyBot hello", Some("MyBot")), "hello");
|
||||||
|
assert_eq!(clean_message_text("@mybot hi", Some("MyBot")), "hi");
|
||||||
|
assert_eq!(
|
||||||
|
clean_message_text("@alice hello", Some("MyBot")),
|
||||||
|
"@alice hello"
|
||||||
|
);
|
||||||
|
assert_eq!(clean_message_text("@MyBot", Some("MyBot")), "");
|
||||||
}
|
}
|
||||||
|
|
||||||
#[test]
|
#[test]
|
||||||
@@ -945,4 +1224,17 @@ mod tests {
|
|||||||
assert_eq!(from.id, 789);
|
assert_eq!(from.id, 789);
|
||||||
assert_eq!(from.first_name, "John");
|
assert_eq!(from.first_name, "John");
|
||||||
}
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_parse_message_with_caption() {
|
||||||
|
let json = r#"{
|
||||||
|
"message_id": 1,
|
||||||
|
"from": {"id": 1, "is_bot": false, "first_name": "A"},
|
||||||
|
"chat": {"id": 1, "type": "private"},
|
||||||
|
"caption": "What's in this image?"
|
||||||
|
}"#;
|
||||||
|
let msg: TelegramMessage = serde_json::from_str(json).unwrap();
|
||||||
|
assert_eq!(msg.text, None);
|
||||||
|
assert_eq!(msg.caption.as_deref(), Some("What's in this image?"));
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,43 +1 @@
|
|||||||
{
|
{"type":"channel","name":"telegram","description":"Telegram Bot API channel for receiving and responding to Telegram messages","capabilities":{"http":{"allowlist":[{"host":"api.telegram.org","path_prefix":"/bot"}],"credentials":{"telegram_bot":{"secret_name":"telegram_bot_token","location":{"type":"url_path","placeholder":"{TELEGRAM_BOT_TOKEN}"},"host_patterns":["api.telegram.org"]}},"rate_limit":{"requests_per_minute":30,"requests_per_hour":1000}},"secrets":{"allowed_names":["telegram_*"]},"channel":{"allowed_paths":["/webhook/telegram"],"allow_polling":true,"min_poll_interval_ms":30000,"workspace_prefix":"channels/telegram/","emit_rate_limit":{"messages_per_minute":100,"messages_per_hour":5000}}},"config":{"bot_username":null,"owner_id":null,"respond_to_all_group_messages":false,"polling_enabled":false,"poll_interval_ms":30000,"dm_policy":"pairing","allow_from":[]}}
|
||||||
"type": "channel",
|
|
||||||
"name": "telegram",
|
|
||||||
"description": "Telegram Bot API channel for receiving and responding to Telegram messages",
|
|
||||||
"capabilities": {
|
|
||||||
"http": {
|
|
||||||
"allowlist": [
|
|
||||||
{ "host": "api.telegram.org", "path_prefix": "/bot" }
|
|
||||||
],
|
|
||||||
"credentials": {
|
|
||||||
"telegram_bot": {
|
|
||||||
"secret_name": "telegram_bot_token",
|
|
||||||
"location": { "type": "url_path", "placeholder": "{TELEGRAM_BOT_TOKEN}" },
|
|
||||||
"host_patterns": ["api.telegram.org"]
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"rate_limit": {
|
|
||||||
"requests_per_minute": 30,
|
|
||||||
"requests_per_hour": 1000
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"secrets": {
|
|
||||||
"allowed_names": ["telegram_*"]
|
|
||||||
},
|
|
||||||
"channel": {
|
|
||||||
"allowed_paths": ["/webhook/telegram"],
|
|
||||||
"allow_polling": true,
|
|
||||||
"min_poll_interval_ms": 30000,
|
|
||||||
"workspace_prefix": "channels/telegram/",
|
|
||||||
"emit_rate_limit": {
|
|
||||||
"messages_per_minute": 100,
|
|
||||||
"messages_per_hour": 5000
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"config": {
|
|
||||||
"bot_username": null,
|
|
||||||
"owner_id": null,
|
|
||||||
"respond_to_all_group_messages": false,
|
|
||||||
"polling_enabled": false,
|
|
||||||
"poll_interval_ms": 30000
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|||||||
Binary file not shown.
@@ -254,10 +254,19 @@ struct WhatsAppChannel;
|
|||||||
|
|
||||||
impl Guest for WhatsAppChannel {
|
impl Guest for WhatsAppChannel {
|
||||||
fn on_start(config_json: String) -> Result<ChannelConfig, String> {
|
fn on_start(config_json: String) -> Result<ChannelConfig, String> {
|
||||||
let config: WhatsAppConfig = serde_json::from_str(&config_json).unwrap_or(WhatsAppConfig {
|
let config: WhatsAppConfig = match serde_json::from_str(&config_json) {
|
||||||
|
Ok(c) => c,
|
||||||
|
Err(e) => {
|
||||||
|
channel_host::log(
|
||||||
|
channel_host::LogLevel::Warn,
|
||||||
|
&format!("Failed to parse WhatsApp config, using defaults: {}", e),
|
||||||
|
);
|
||||||
|
WhatsAppConfig {
|
||||||
api_version: default_api_version(),
|
api_version: default_api_version(),
|
||||||
reply_to_message: default_reply_to_message(),
|
reply_to_message: default_reply_to_message(),
|
||||||
});
|
}
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
channel_host::log(
|
channel_host::log(
|
||||||
channel_host::LogLevel::Info,
|
channel_host::LogLevel::Info,
|
||||||
@@ -267,6 +276,9 @@ impl Guest for WhatsAppChannel {
|
|||||||
),
|
),
|
||||||
);
|
);
|
||||||
|
|
||||||
|
// Persist api_version in workspace so on_respond() can read it
|
||||||
|
let _ = channel_host::workspace_write("channels/whatsapp/api_version", &config.api_version);
|
||||||
|
|
||||||
// WhatsApp Cloud API is webhook-only, no polling available
|
// WhatsApp Cloud API is webhook-only, no polling available
|
||||||
Ok(ChannelConfig {
|
Ok(ChannelConfig {
|
||||||
display_name: "WhatsApp".to_string(),
|
display_name: "WhatsApp".to_string(),
|
||||||
@@ -327,11 +339,16 @@ impl Guest for WhatsAppChannel {
|
|||||||
let metadata: WhatsAppMessageMetadata = serde_json::from_str(&response.metadata_json)
|
let metadata: WhatsAppMessageMetadata = serde_json::from_str(&response.metadata_json)
|
||||||
.map_err(|e| format!("Failed to parse metadata: {}", e))?;
|
.map_err(|e| format!("Failed to parse metadata: {}", e))?;
|
||||||
|
|
||||||
|
// Read api_version from workspace (set during on_start), fallback to default
|
||||||
|
let api_version = channel_host::workspace_read("channels/whatsapp/api_version")
|
||||||
|
.filter(|s| !s.is_empty())
|
||||||
|
.unwrap_or_else(|| "v18.0".to_string());
|
||||||
|
|
||||||
// Build WhatsApp API URL with token placeholder
|
// Build WhatsApp API URL with token placeholder
|
||||||
// Host will replace {WHATSAPP_ACCESS_TOKEN} with actual token in Authorization header
|
// Host will replace {WHATSAPP_ACCESS_TOKEN} with actual token in Authorization header
|
||||||
let api_url = format!(
|
let api_url = format!(
|
||||||
"https://graph.facebook.com/v18.0/{}/messages",
|
"https://graph.facebook.com/{}/{}/messages",
|
||||||
metadata.phone_number_id
|
api_version, metadata.phone_number_id
|
||||||
);
|
);
|
||||||
|
|
||||||
// Build sendMessage payload
|
// Build sendMessage payload
|
||||||
@@ -361,6 +378,7 @@ impl Guest for WhatsAppChannel {
|
|||||||
&api_url,
|
&api_url,
|
||||||
&headers.to_string(),
|
&headers.to_string(),
|
||||||
Some(&payload_bytes),
|
Some(&payload_bytes),
|
||||||
|
None,
|
||||||
);
|
);
|
||||||
|
|
||||||
match result {
|
match result {
|
||||||
|
|||||||
@@ -0,0 +1,13 @@
|
|||||||
|
[Unit]
|
||||||
|
Description=Cloud SQL Auth Proxy
|
||||||
|
After=network.target
|
||||||
|
|
||||||
|
[Service]
|
||||||
|
Type=simple
|
||||||
|
DynamicUser=yes
|
||||||
|
ExecStart=/usr/local/bin/cloud-sql-proxy ironclaw-prod:us-central1:ironclaw-db --port=5432
|
||||||
|
Restart=always
|
||||||
|
RestartSec=5
|
||||||
|
|
||||||
|
[Install]
|
||||||
|
WantedBy=multi-user.target
|
||||||
@@ -0,0 +1,27 @@
|
|||||||
|
# WARNING: Replace all CHANGE_ME values before deploying.
|
||||||
|
# Do not use placeholder passwords in production.
|
||||||
|
DATABASE_URL=postgres://ironclaw:CHANGE_ME@localhost:5432/ironclaw
|
||||||
|
|
||||||
|
# NEAR AI
|
||||||
|
NEARAI_SESSION_TOKEN=CHANGE_ME
|
||||||
|
NEARAI_MODEL=claude-3-5-sonnet-20241022
|
||||||
|
NEARAI_BASE_URL=https://cloud-api.near.ai
|
||||||
|
NEARAI_AUTH_URL=https://private.near.ai
|
||||||
|
NEARAI_API_MODE=chat_completions
|
||||||
|
|
||||||
|
# Agent
|
||||||
|
AGENT_NAME=ironclaw
|
||||||
|
CLI_ENABLED=false
|
||||||
|
|
||||||
|
# Web Gateway
|
||||||
|
GATEWAY_ENABLED=true
|
||||||
|
# 0.0.0.0 binds to all interfaces (required for Docker --network=host).
|
||||||
|
# Use 127.0.0.1 if running outside Docker or for local-only access.
|
||||||
|
GATEWAY_HOST=0.0.0.0
|
||||||
|
GATEWAY_PORT=3000
|
||||||
|
GATEWAY_AUTH_TOKEN=CHANGE_ME
|
||||||
|
|
||||||
|
# Disabled for initial deploy
|
||||||
|
SANDBOX_ENABLED=false
|
||||||
|
HEARTBEAT_ENABLED=false
|
||||||
|
EMBEDDING_ENABLED=false
|
||||||
@@ -0,0 +1,20 @@
|
|||||||
|
[Unit]
|
||||||
|
Description=IronClaw AI Assistant
|
||||||
|
After=cloud-sql-proxy.service docker.service
|
||||||
|
Requires=cloud-sql-proxy.service
|
||||||
|
|
||||||
|
[Service]
|
||||||
|
Type=simple
|
||||||
|
ExecStartPre=/usr/bin/docker pull us-central1-docker.pkg.dev/ironclaw-prod/ironclaw/agent:latest
|
||||||
|
ExecStart=/usr/bin/docker run --rm \
|
||||||
|
--name ironclaw \
|
||||||
|
--env-file /opt/ironclaw/.env \
|
||||||
|
--network=host \
|
||||||
|
us-central1-docker.pkg.dev/ironclaw-prod/ironclaw/agent:latest \
|
||||||
|
--no-onboard
|
||||||
|
ExecStop=/usr/bin/docker stop ironclaw
|
||||||
|
Restart=always
|
||||||
|
RestartSec=10
|
||||||
|
|
||||||
|
[Install]
|
||||||
|
WantedBy=multi-user.target
|
||||||
Executable
+68
@@ -0,0 +1,68 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
# VM bootstrap script for IronClaw on GCP Compute Engine.
|
||||||
|
#
|
||||||
|
# Run on a fresh Debian 12 VM after SSH:
|
||||||
|
# sudo bash setup.sh
|
||||||
|
#
|
||||||
|
# Prerequisites:
|
||||||
|
# - VM has the ironclaw-vm service account attached
|
||||||
|
# - Cloud SQL Auth Proxy accessible via IAM
|
||||||
|
# - Artifact Registry image pushed
|
||||||
|
|
||||||
|
set -euo pipefail
|
||||||
|
|
||||||
|
# Must run as root
|
||||||
|
if [ "$(id -u)" -ne 0 ]; then
|
||||||
|
echo "ERROR: This script must be run as root (sudo bash setup.sh)"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
echo "==> Installing Docker"
|
||||||
|
apt-get update
|
||||||
|
apt-get install -y docker.io
|
||||||
|
systemctl enable docker
|
||||||
|
systemctl start docker
|
||||||
|
|
||||||
|
echo "==> Installing Cloud SQL Auth Proxy"
|
||||||
|
curl -fsSL -o /usr/local/bin/cloud-sql-proxy \
|
||||||
|
https://storage.googleapis.com/cloud-sql-connectors/cloud-sql-proxy/v2.14.3/cloud-sql-proxy.linux.amd64
|
||||||
|
chmod +x /usr/local/bin/cloud-sql-proxy
|
||||||
|
|
||||||
|
echo "==> Installing systemd services"
|
||||||
|
cp /tmp/deploy/cloud-sql-proxy.service /etc/systemd/system/
|
||||||
|
cp /tmp/deploy/ironclaw.service /etc/systemd/system/
|
||||||
|
systemctl daemon-reload
|
||||||
|
|
||||||
|
echo "==> Starting Cloud SQL Auth Proxy"
|
||||||
|
systemctl enable cloud-sql-proxy
|
||||||
|
systemctl start cloud-sql-proxy
|
||||||
|
|
||||||
|
echo "==> Configuring Docker registry auth"
|
||||||
|
# The VM service account provides Artifact Registry access
|
||||||
|
gcloud auth configure-docker us-central1-docker.pkg.dev --quiet
|
||||||
|
|
||||||
|
echo "==> Creating config directory"
|
||||||
|
# Owned by root, readable only by root. Docker reads --env-file as root
|
||||||
|
# before dropping to uid 1000 (ironclaw) inside the container.
|
||||||
|
mkdir -p /opt/ironclaw
|
||||||
|
chmod 700 /opt/ironclaw
|
||||||
|
|
||||||
|
if [ ! -f /opt/ironclaw/.env ]; then
|
||||||
|
echo "WARNING: /opt/ironclaw/.env does not exist."
|
||||||
|
echo "Create it with your configuration before starting IronClaw."
|
||||||
|
echo "See deploy/env.example for the required variables."
|
||||||
|
echo ""
|
||||||
|
echo "Then run: systemctl enable ironclaw && systemctl start ironclaw"
|
||||||
|
else
|
||||||
|
chmod 600 /opt/ironclaw/.env
|
||||||
|
echo "==> Starting IronClaw"
|
||||||
|
systemctl enable ironclaw
|
||||||
|
systemctl start ironclaw
|
||||||
|
fi
|
||||||
|
|
||||||
|
echo "==> Setup complete"
|
||||||
|
echo ""
|
||||||
|
echo "Verify with:"
|
||||||
|
echo " systemctl status cloud-sql-proxy"
|
||||||
|
echo " systemctl status ironclaw"
|
||||||
|
echo " docker logs ironclaw"
|
||||||
@@ -0,0 +1,20 @@
|
|||||||
|
# Local development only — do NOT use these credentials in production.
|
||||||
|
services:
|
||||||
|
postgres:
|
||||||
|
image: pgvector/pgvector:pg16
|
||||||
|
ports:
|
||||||
|
- "5432:5432"
|
||||||
|
environment:
|
||||||
|
POSTGRES_DB: ironclaw
|
||||||
|
POSTGRES_USER: ironclaw
|
||||||
|
POSTGRES_PASSWORD: ironclaw # dev-only, change for any non-local deployment
|
||||||
|
volumes:
|
||||||
|
- pgdata:/var/lib/postgresql/data
|
||||||
|
healthcheck:
|
||||||
|
test: ["CMD-SHELL", "pg_isready -U ironclaw"]
|
||||||
|
interval: 5s
|
||||||
|
timeout: 3s
|
||||||
|
retries: 5
|
||||||
|
|
||||||
|
volumes:
|
||||||
|
pgdata:
|
||||||
@@ -246,13 +246,46 @@ Create `my-channel.capabilities.json`:
|
|||||||
|
|
||||||
## Building and Deploying
|
## Building and Deploying
|
||||||
|
|
||||||
|
### Supply Chain Security: No Committed Binaries
|
||||||
|
|
||||||
|
**Do not commit compiled WASM binaries.** They are a supply chain risk — the binary in a PR may not match the source. IronClaw builds channels from source:
|
||||||
|
|
||||||
|
- `cargo build` automatically builds `telegram.wasm` via `build.rs`
|
||||||
|
- The built binary is in `.gitignore` and is not committed
|
||||||
|
- CI should run `cargo build` (or `./scripts/build-all.sh`) to produce releases
|
||||||
|
|
||||||
|
**Reproducible build:**
|
||||||
|
```bash
|
||||||
|
cargo build --release
|
||||||
|
```
|
||||||
|
|
||||||
|
Prerequisites: `rustup target add wasm32-wasip2`, `cargo install wasm-tools` (optional; fallback copies raw WASM if unavailable).
|
||||||
|
|
||||||
|
### Telegram Channel (Manual Build)
|
||||||
|
|
||||||
|
```bash
|
||||||
|
# Add WASM target if needed
|
||||||
|
rustup target add wasm32-wasip2
|
||||||
|
|
||||||
|
# Build Telegram channel
|
||||||
|
./channels-src/telegram/build.sh
|
||||||
|
|
||||||
|
# Install (or use ironclaw onboard to install bundled channel)
|
||||||
|
mkdir -p ~/.ironclaw/channels
|
||||||
|
cp channels-src/telegram/telegram.wasm channels-src/telegram/telegram.capabilities.json ~/.ironclaw/channels/
|
||||||
|
```
|
||||||
|
|
||||||
|
**Note**: The main IronClaw binary bundles `telegram.wasm` via `include_bytes!`. When modifying the Telegram channel source, run `./channels-src/telegram/build.sh` **before** building the main crate, so the updated WASM is included.
|
||||||
|
|
||||||
|
### Other Channels
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
# Build the WASM component
|
# Build the WASM component
|
||||||
cd channels/my-channel
|
cd channels-src/my-channel
|
||||||
cargo component build --release
|
cargo build --release --target wasm32-wasip2
|
||||||
|
|
||||||
# Deploy to ~/.ironclaw/channels/
|
# Deploy to ~/.ironclaw/channels/
|
||||||
cp target/wasm32-wasip1/release/my_channel.wasm ~/.ironclaw/channels/my-channel.wasm
|
cp target/wasm32-wasip2/release/my_channel.wasm ~/.ironclaw/channels/my-channel.wasm
|
||||||
cp my-channel.capabilities.json ~/.ironclaw/channels/
|
cp my-channel.capabilities.json ~/.ironclaw/channels/
|
||||||
```
|
```
|
||||||
|
|
||||||
|
|||||||
@@ -0,0 +1,135 @@
|
|||||||
|
# Telegram Channel Setup
|
||||||
|
|
||||||
|
This guide covers configuring the Telegram channel for IronClaw, including DM pairing for access control.
|
||||||
|
|
||||||
|
## Overview
|
||||||
|
|
||||||
|
The Telegram channel lets you interact with IronClaw via Telegram DMs and groups. It supports:
|
||||||
|
|
||||||
|
- **Webhook mode** (recommended): Instant delivery via tunnel
|
||||||
|
- **Polling mode**: No tunnel required; ~30s delay
|
||||||
|
- **DM pairing**: Approve unknown users before they can message the agent
|
||||||
|
- **Group mentions**: `@YourBot` or `/command` to trigger in groups
|
||||||
|
|
||||||
|
## Prerequisites
|
||||||
|
|
||||||
|
- IronClaw installed and configured (`ironclaw onboard`)
|
||||||
|
- A Telegram bot token from [@BotFather](https://t.me/BotFather)
|
||||||
|
|
||||||
|
## Quick Start
|
||||||
|
|
||||||
|
### 1. Create a Bot
|
||||||
|
|
||||||
|
1. Message [@BotFather](https://t.me/BotFather) on Telegram
|
||||||
|
2. Send `/newbot` and follow the prompts
|
||||||
|
3. Copy the bot token (e.g., `123456789:ABCdefGHIjklMNOpqrsTUVwxyz`)
|
||||||
|
|
||||||
|
### 2. Configure via Setup Wizard
|
||||||
|
|
||||||
|
```bash
|
||||||
|
ironclaw onboard
|
||||||
|
```
|
||||||
|
|
||||||
|
When prompted, enable the Telegram channel and paste your bot token. The wizard will:
|
||||||
|
|
||||||
|
- Validate the token
|
||||||
|
- Optionally configure a webhook secret
|
||||||
|
- Set up tunnel (if you want webhook mode)
|
||||||
|
|
||||||
|
### 3. (Optional) Configure Tunnel for Webhooks
|
||||||
|
|
||||||
|
For instant message delivery, expose your agent via a tunnel:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
# ngrok
|
||||||
|
ngrok http 8080
|
||||||
|
|
||||||
|
# Cloudflare
|
||||||
|
cloudflared tunnel --url http://localhost:8080
|
||||||
|
```
|
||||||
|
|
||||||
|
Set the tunnel URL in settings or via `TUNNEL_URL` env var. Without a tunnel, the channel uses polling (~30s delay).
|
||||||
|
|
||||||
|
## DM Pairing
|
||||||
|
|
||||||
|
When an unknown user DMs your bot, they receive a pairing code. You must approve them before they can message the agent.
|
||||||
|
|
||||||
|
### Flow
|
||||||
|
|
||||||
|
1. Unknown user sends a message to your bot
|
||||||
|
2. Bot replies: `To pair with this bot, run: ironclaw pairing approve telegram ABC12345`
|
||||||
|
3. You run: `ironclaw pairing approve telegram ABC12345`
|
||||||
|
4. User is added to the allow list; future messages are delivered
|
||||||
|
|
||||||
|
### Commands
|
||||||
|
|
||||||
|
```bash
|
||||||
|
# List pending pairing requests
|
||||||
|
ironclaw pairing list telegram
|
||||||
|
|
||||||
|
# List as JSON
|
||||||
|
ironclaw pairing list telegram --json
|
||||||
|
|
||||||
|
# Approve a user by code
|
||||||
|
ironclaw pairing approve telegram ABC12345
|
||||||
|
```
|
||||||
|
|
||||||
|
### Configuration
|
||||||
|
|
||||||
|
Edit `~/.ironclaw/channels/telegram.capabilities.json` (or the config injected by the host):
|
||||||
|
|
||||||
|
| Option | Values | Default | Description |
|
||||||
|
|--------|--------|---------|-------------|
|
||||||
|
| `dm_policy` | `open`, `allowlist`, `pairing` | `pairing` | `open` = allow all; `allowlist` = config + approved only; `pairing` = allowlist + send pairing reply to unknown |
|
||||||
|
| `allow_from` | `["user_id", "username", "*"]` | `[]` | Pre-approved IDs/usernames. `*` allows everyone. |
|
||||||
|
| `owner_id` | Telegram user ID | `null` | When set, only this user can message (overrides dm_policy) |
|
||||||
|
| `bot_username` | Bot username (no @) | `null` | Used for mention detection in groups; when set, only strips this mention from messages |
|
||||||
|
| `respond_to_all_group_messages` | `true`/`false` | `false` | When true, respond to all group messages; when false, only @mentions and /commands |
|
||||||
|
|
||||||
|
## Manual Installation
|
||||||
|
|
||||||
|
If the channel isn't installed via the wizard:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
# Build the Telegram channel (requires wasm32-wasip2 target)
|
||||||
|
rustup target add wasm32-wasip2
|
||||||
|
./channels-src/telegram/build.sh
|
||||||
|
|
||||||
|
# Install
|
||||||
|
mkdir -p ~/.ironclaw/channels
|
||||||
|
cp channels-src/telegram/telegram.wasm channels-src/telegram/telegram.capabilities.json ~/.ironclaw/channels/
|
||||||
|
```
|
||||||
|
|
||||||
|
## Secrets
|
||||||
|
|
||||||
|
The channel expects a secret named `telegram_bot_token`. Configure via:
|
||||||
|
|
||||||
|
- **Setup wizard**: Saves to encrypted secrets store
|
||||||
|
- **Environment**: `TELEGRAM_BOT_TOKEN=your_token`
|
||||||
|
- **Secrets store**: `ironclaw` CLI (if available)
|
||||||
|
|
||||||
|
## Webhook Secret (Optional)
|
||||||
|
|
||||||
|
For webhook validation, set `telegram_webhook_secret` in secrets. Telegram will send `X-Telegram-Bot-Api-Secret-Token` with each request; the host validates it before forwarding.
|
||||||
|
|
||||||
|
## Troubleshooting
|
||||||
|
|
||||||
|
### Messages not delivered
|
||||||
|
|
||||||
|
- **Polling mode**: Check logs for `getUpdates` errors. Ensure the bot token is valid.
|
||||||
|
- **Webhook mode**: Verify tunnel is running and `TUNNEL_URL` is correct. Telegram requires HTTPS.
|
||||||
|
|
||||||
|
### Pairing code not received
|
||||||
|
|
||||||
|
- Verify the channel can send messages (HTTP allowlist includes `api.telegram.org`)
|
||||||
|
- Check `dm_policy` is `pairing` (not `allowlist` which blocks without reply)
|
||||||
|
|
||||||
|
### Group mentions not working
|
||||||
|
|
||||||
|
- Set `bot_username` in config to your bot's username (e.g., `MyIronClawBot`)
|
||||||
|
- Ensure the message contains `@YourBot` or starts with `/`
|
||||||
|
|
||||||
|
### "Connection refused" when starting
|
||||||
|
|
||||||
|
- For webhook mode: Start your tunnel before `ironclaw run`
|
||||||
|
- For polling only: No tunnel needed; ignore tunnel-related warnings
|
||||||
@@ -0,0 +1,121 @@
|
|||||||
|
//! Standalone heartbeat test.
|
||||||
|
//!
|
||||||
|
//! Exercises the heartbeat system in isolation: connects to the real
|
||||||
|
//! database, reads the real HEARTBEAT.md, calls the real LLM, and prints
|
||||||
|
//! every step so you can see exactly where it breaks.
|
||||||
|
//!
|
||||||
|
//! Usage:
|
||||||
|
//! cargo run --example test_heartbeat
|
||||||
|
|
||||||
|
use std::sync::Arc;
|
||||||
|
|
||||||
|
use ironclaw::{
|
||||||
|
agent::HeartbeatRunner,
|
||||||
|
config::Config,
|
||||||
|
history::Store,
|
||||||
|
llm::{SessionConfig, create_llm_provider, create_session_manager},
|
||||||
|
workspace::Workspace,
|
||||||
|
};
|
||||||
|
|
||||||
|
#[tokio::main]
|
||||||
|
async fn main() -> anyhow::Result<()> {
|
||||||
|
// Load .env and set up logging
|
||||||
|
let _ = dotenvy::dotenv();
|
||||||
|
tracing_subscriber::fmt()
|
||||||
|
.with_env_filter("ironclaw=debug")
|
||||||
|
.init();
|
||||||
|
|
||||||
|
println!("=== Heartbeat Integration Test ===\n");
|
||||||
|
|
||||||
|
// 1. Load config
|
||||||
|
let config = Config::from_env()
|
||||||
|
.await
|
||||||
|
.map_err(|e| anyhow::anyhow!("Config: {}", e))?;
|
||||||
|
println!("[1/6] Config loaded");
|
||||||
|
println!(" heartbeat.enabled = {}", config.heartbeat.enabled);
|
||||||
|
println!(
|
||||||
|
" heartbeat.interval_secs = {}",
|
||||||
|
config.heartbeat.interval_secs
|
||||||
|
);
|
||||||
|
println!(
|
||||||
|
" heartbeat.notify_channel = {:?}",
|
||||||
|
config.heartbeat.notify_channel
|
||||||
|
);
|
||||||
|
println!(
|
||||||
|
" heartbeat.notify_user = {:?}",
|
||||||
|
config.heartbeat.notify_user
|
||||||
|
);
|
||||||
|
|
||||||
|
// 2. Connect to database
|
||||||
|
let store = Store::new(&config.database).await?;
|
||||||
|
store.run_migrations().await?;
|
||||||
|
println!("[2/6] Database connected");
|
||||||
|
|
||||||
|
// 3. Create workspace
|
||||||
|
let workspace = Arc::new(Workspace::new("default", store.pool()));
|
||||||
|
println!("[3/6] Workspace created");
|
||||||
|
|
||||||
|
// 4. Read HEARTBEAT.md
|
||||||
|
let checklist = workspace.heartbeat_checklist().await;
|
||||||
|
match &checklist {
|
||||||
|
Ok(Some(content)) => {
|
||||||
|
let preview: String = content.chars().take(200).collect();
|
||||||
|
println!("[4/6] HEARTBEAT.md found ({} chars)", content.len());
|
||||||
|
println!(" Preview: {}...", preview);
|
||||||
|
}
|
||||||
|
Ok(None) => {
|
||||||
|
println!("[4/6] HEARTBEAT.md is None (no file, no seed fallback)");
|
||||||
|
println!(" Heartbeat will return Skipped.");
|
||||||
|
}
|
||||||
|
Err(e) => {
|
||||||
|
println!("[4/6] HEARTBEAT.md read error: {}", e);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// Check if the checklist would be considered "effectively empty"
|
||||||
|
if let Ok(Some(_)) = checklist {
|
||||||
|
println!(" (Will verify via runner below)");
|
||||||
|
}
|
||||||
|
|
||||||
|
// 5. Create LLM provider
|
||||||
|
let session = create_session_manager(SessionConfig {
|
||||||
|
auth_base_url: config.llm.nearai.auth_base_url.clone(),
|
||||||
|
session_path: config.llm.nearai.session_path.clone(),
|
||||||
|
})
|
||||||
|
.await;
|
||||||
|
let llm = create_llm_provider(&config.llm, session)?;
|
||||||
|
println!("[5/6] LLM provider created (model: {})", llm.model_name());
|
||||||
|
|
||||||
|
// 6. Run heartbeat check
|
||||||
|
println!("[6/6] Running check_heartbeat()...\n");
|
||||||
|
|
||||||
|
let hb_config = ironclaw::agent::HeartbeatConfig::default();
|
||||||
|
let runner = HeartbeatRunner::new(hb_config, workspace, llm);
|
||||||
|
|
||||||
|
let result = runner.check_heartbeat().await;
|
||||||
|
|
||||||
|
println!("=== Result ===\n");
|
||||||
|
match &result {
|
||||||
|
ironclaw::agent::HeartbeatResult::Ok => {
|
||||||
|
println!("HeartbeatResult::Ok");
|
||||||
|
println!(" LLM responded HEARTBEAT_OK, nothing needs attention.");
|
||||||
|
}
|
||||||
|
ironclaw::agent::HeartbeatResult::NeedsAttention(msg) => {
|
||||||
|
println!("HeartbeatResult::NeedsAttention");
|
||||||
|
println!(" Message:\n{}", msg);
|
||||||
|
}
|
||||||
|
ironclaw::agent::HeartbeatResult::Skipped => {
|
||||||
|
println!("HeartbeatResult::Skipped");
|
||||||
|
println!(" No checklist found, or checklist was effectively empty.");
|
||||||
|
println!(" This means the HEARTBEAT.md either:");
|
||||||
|
println!(" - Does not exist in the workspace database");
|
||||||
|
println!(" - Contains only headers, comments, and empty checkboxes");
|
||||||
|
}
|
||||||
|
ironclaw::agent::HeartbeatResult::Failed(err) => {
|
||||||
|
println!("HeartbeatResult::Failed");
|
||||||
|
println!(" Error: {}", err);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
Ok(())
|
||||||
|
}
|
||||||
@@ -0,0 +1,10 @@
|
|||||||
|
-- Add project_dir and user_id columns for sandbox job tracking.
|
||||||
|
-- user_id was previously hardcoded to "default" in the Rust layer;
|
||||||
|
-- now it's persisted so we can filter per-user.
|
||||||
|
|
||||||
|
ALTER TABLE agent_jobs ADD COLUMN IF NOT EXISTS project_dir TEXT;
|
||||||
|
ALTER TABLE agent_jobs ADD COLUMN IF NOT EXISTS user_id TEXT NOT NULL DEFAULT 'default';
|
||||||
|
|
||||||
|
CREATE INDEX IF NOT EXISTS idx_agent_jobs_source ON agent_jobs(source);
|
||||||
|
CREATE INDEX IF NOT EXISTS idx_agent_jobs_user ON agent_jobs(user_id);
|
||||||
|
CREATE INDEX IF NOT EXISTS idx_agent_jobs_created ON agent_jobs(created_at DESC);
|
||||||
@@ -0,0 +1,14 @@
|
|||||||
|
-- Track which mode a sandbox job uses (worker vs claude_code).
|
||||||
|
ALTER TABLE agent_jobs ADD COLUMN IF NOT EXISTS job_mode TEXT NOT NULL DEFAULT 'worker';
|
||||||
|
|
||||||
|
-- Persist Claude Code streaming events so they survive restarts and can be
|
||||||
|
-- loaded when the frontend opens a job detail view after the fact.
|
||||||
|
CREATE TABLE IF NOT EXISTS claude_code_events (
|
||||||
|
id BIGSERIAL PRIMARY KEY,
|
||||||
|
job_id UUID NOT NULL REFERENCES agent_jobs(id),
|
||||||
|
event_type TEXT NOT NULL,
|
||||||
|
data JSONB NOT NULL,
|
||||||
|
created_at TIMESTAMPTZ NOT NULL DEFAULT now()
|
||||||
|
);
|
||||||
|
|
||||||
|
CREATE INDEX IF NOT EXISTS idx_cc_events_job ON claude_code_events(job_id, id);
|
||||||
@@ -0,0 +1,73 @@
|
|||||||
|
-- Routines: scheduled and reactive job system.
|
||||||
|
--
|
||||||
|
-- A routine is a named, persistent, user-owned task with a trigger and an action.
|
||||||
|
-- Triggers fire independently (cron, event, webhook, manual) so only the
|
||||||
|
-- relevant routine's prompt hits the LLM, not the whole checklist.
|
||||||
|
|
||||||
|
CREATE TABLE routines (
|
||||||
|
id UUID PRIMARY KEY DEFAULT gen_random_uuid(),
|
||||||
|
name TEXT NOT NULL,
|
||||||
|
description TEXT NOT NULL DEFAULT '',
|
||||||
|
user_id TEXT NOT NULL,
|
||||||
|
enabled BOOLEAN NOT NULL DEFAULT true,
|
||||||
|
|
||||||
|
-- Trigger definition
|
||||||
|
trigger_type TEXT NOT NULL, -- 'cron', 'event', 'webhook', 'manual'
|
||||||
|
trigger_config JSONB NOT NULL, -- type-specific config (schedule, pattern, etc.)
|
||||||
|
|
||||||
|
-- Action definition
|
||||||
|
action_type TEXT NOT NULL, -- 'lightweight', 'full_job'
|
||||||
|
action_config JSONB NOT NULL, -- prompt, context_paths, max_tokens / title, max_iterations
|
||||||
|
|
||||||
|
-- Guardrails
|
||||||
|
cooldown_secs INTEGER NOT NULL DEFAULT 300,
|
||||||
|
max_concurrent INTEGER NOT NULL DEFAULT 1,
|
||||||
|
dedup_window_secs INTEGER, -- NULL = no dedup
|
||||||
|
|
||||||
|
-- Notification preferences
|
||||||
|
notify_channel TEXT, -- NULL = use default
|
||||||
|
notify_user TEXT NOT NULL DEFAULT 'default',
|
||||||
|
notify_on_success BOOLEAN NOT NULL DEFAULT false,
|
||||||
|
notify_on_failure BOOLEAN NOT NULL DEFAULT true,
|
||||||
|
notify_on_attention BOOLEAN NOT NULL DEFAULT true,
|
||||||
|
|
||||||
|
-- Runtime state (updated by engine)
|
||||||
|
state JSONB NOT NULL DEFAULT '{}',
|
||||||
|
last_run_at TIMESTAMPTZ,
|
||||||
|
next_fire_at TIMESTAMPTZ, -- pre-computed for cron triggers
|
||||||
|
run_count BIGINT NOT NULL DEFAULT 0,
|
||||||
|
consecutive_failures INTEGER NOT NULL DEFAULT 0,
|
||||||
|
|
||||||
|
created_at TIMESTAMPTZ NOT NULL DEFAULT now(),
|
||||||
|
updated_at TIMESTAMPTZ NOT NULL DEFAULT now(),
|
||||||
|
|
||||||
|
UNIQUE (user_id, name)
|
||||||
|
);
|
||||||
|
|
||||||
|
-- Fast lookup: "which cron routines need to fire right now?"
|
||||||
|
CREATE INDEX idx_routines_next_fire
|
||||||
|
ON routines (next_fire_at)
|
||||||
|
WHERE enabled AND next_fire_at IS NOT NULL;
|
||||||
|
|
||||||
|
-- Fast lookup: event triggers for a user
|
||||||
|
CREATE INDEX idx_routines_event_triggers
|
||||||
|
ON routines (user_id)
|
||||||
|
WHERE enabled AND trigger_type = 'event';
|
||||||
|
|
||||||
|
-- Audit log of individual routine executions.
|
||||||
|
CREATE TABLE routine_runs (
|
||||||
|
id UUID PRIMARY KEY DEFAULT gen_random_uuid(),
|
||||||
|
routine_id UUID NOT NULL REFERENCES routines(id) ON DELETE CASCADE,
|
||||||
|
trigger_type TEXT NOT NULL,
|
||||||
|
trigger_detail TEXT, -- e.g. matched message preview, cron expression
|
||||||
|
started_at TIMESTAMPTZ NOT NULL DEFAULT now(),
|
||||||
|
completed_at TIMESTAMPTZ,
|
||||||
|
status TEXT NOT NULL DEFAULT 'running', -- running, ok, attention, failed
|
||||||
|
result_summary TEXT,
|
||||||
|
tokens_used INTEGER,
|
||||||
|
job_id UUID REFERENCES agent_jobs(id), -- non-NULL for full_job runs
|
||||||
|
created_at TIMESTAMPTZ NOT NULL DEFAULT now()
|
||||||
|
);
|
||||||
|
|
||||||
|
CREATE INDEX idx_routine_runs_routine ON routine_runs (routine_id);
|
||||||
|
CREATE INDEX idx_routine_runs_status ON routine_runs (status) WHERE status = 'running';
|
||||||
@@ -0,0 +1,3 @@
|
|||||||
|
-- Rename claude_code_events to job_events (generic for all sandbox job types).
|
||||||
|
ALTER TABLE claude_code_events RENAME TO job_events;
|
||||||
|
ALTER INDEX idx_cc_events_job RENAME TO idx_job_events_job;
|
||||||
@@ -0,0 +1,16 @@
|
|||||||
|
-- Settings table: key-value store for all user configuration.
|
||||||
|
--
|
||||||
|
-- Replaces ~/.ironclaw/settings.json, session.json, and mcp-servers.json.
|
||||||
|
-- Keys use dotted paths matching the existing Settings.get()/set() convention
|
||||||
|
-- (e.g., "agent.name", "sandbox.enabled", "mcp_servers").
|
||||||
|
-- One row per setting so individual values can be updated atomically.
|
||||||
|
|
||||||
|
CREATE TABLE IF NOT EXISTS settings (
|
||||||
|
user_id TEXT NOT NULL,
|
||||||
|
key TEXT NOT NULL,
|
||||||
|
value JSONB NOT NULL,
|
||||||
|
updated_at TIMESTAMPTZ NOT NULL DEFAULT NOW(),
|
||||||
|
PRIMARY KEY (user_id, key)
|
||||||
|
);
|
||||||
|
|
||||||
|
CREATE INDEX IF NOT EXISTS idx_settings_user ON settings (user_id);
|
||||||
@@ -0,0 +1,2 @@
|
|||||||
|
[workspace]
|
||||||
|
git_release_enable = false
|
||||||
Executable
+21
@@ -0,0 +1,21 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
# Build IronClaw and all bundled channels.
|
||||||
|
#
|
||||||
|
# Run this before release or when channel sources have changed.
|
||||||
|
# The main binary bundles telegram.wasm via include_bytes!; it must exist.
|
||||||
|
|
||||||
|
set -euo pipefail
|
||||||
|
|
||||||
|
cd "$(dirname "$0")/.."
|
||||||
|
|
||||||
|
echo "Building bundled channels..."
|
||||||
|
if [ -d "channels-src/telegram" ]; then
|
||||||
|
./channels-src/telegram/build.sh
|
||||||
|
fi
|
||||||
|
|
||||||
|
echo ""
|
||||||
|
echo "Building IronClaw..."
|
||||||
|
cargo build --release
|
||||||
|
|
||||||
|
echo ""
|
||||||
|
echo "Done. Binary: target/release/ironclaw"
|
||||||
+779
-142
File diff suppressed because it is too large
Load Diff
+34
-3
@@ -29,7 +29,7 @@ use std::time::Duration;
|
|||||||
use tokio::sync::mpsc;
|
use tokio::sync::mpsc;
|
||||||
|
|
||||||
use crate::channels::OutgoingResponse;
|
use crate::channels::OutgoingResponse;
|
||||||
use crate::llm::{ChatMessage, CompletionRequest, LlmProvider};
|
use crate::llm::{ChatMessage, CompletionRequest, FinishReason, LlmProvider};
|
||||||
use crate::workspace::Workspace;
|
use crate::workspace::Workspace;
|
||||||
|
|
||||||
/// Configuration for the heartbeat runner.
|
/// Configuration for the heartbeat runner.
|
||||||
@@ -217,9 +217,26 @@ impl HeartbeatRunner {
|
|||||||
]
|
]
|
||||||
};
|
};
|
||||||
|
|
||||||
|
// Use the model's context_length to set max_tokens. The API returns
|
||||||
|
// the total context window; we cap output at half of that (the rest is
|
||||||
|
// the prompt) with a floor of 4096.
|
||||||
|
let max_tokens = match self.llm.model_metadata().await {
|
||||||
|
Ok(meta) => {
|
||||||
|
let from_api = meta.context_length.map(|ctx| ctx / 2).unwrap_or(4096);
|
||||||
|
from_api.max(4096)
|
||||||
|
}
|
||||||
|
Err(e) => {
|
||||||
|
tracing::warn!(
|
||||||
|
"Could not fetch model metadata, using default max_tokens: {}",
|
||||||
|
e
|
||||||
|
);
|
||||||
|
4096
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
let request = CompletionRequest::new(messages)
|
let request = CompletionRequest::new(messages)
|
||||||
.with_max_tokens(1024)
|
.with_max_tokens(max_tokens)
|
||||||
.with_temperature(0.3); // Lower temperature for more focused responses
|
.with_temperature(0.3);
|
||||||
|
|
||||||
let response = match self.llm.complete(request).await {
|
let response = match self.llm.complete(request).await {
|
||||||
Ok(r) => r,
|
Ok(r) => r,
|
||||||
@@ -228,6 +245,20 @@ impl HeartbeatRunner {
|
|||||||
|
|
||||||
let content = response.content.trim();
|
let content = response.content.trim();
|
||||||
|
|
||||||
|
// Guard against empty content. Reasoning models (e.g. GLM-4.7) may
|
||||||
|
// burn all output tokens on chain-of-thought and return content: null.
|
||||||
|
if content.is_empty() {
|
||||||
|
return if response.finish_reason == FinishReason::Length {
|
||||||
|
HeartbeatResult::Failed(
|
||||||
|
"LLM response was truncated (finish_reason=length) with no content. \
|
||||||
|
The model may have exhausted its token budget on reasoning."
|
||||||
|
.to_string(),
|
||||||
|
)
|
||||||
|
} else {
|
||||||
|
HeartbeatResult::Failed("LLM returned empty content.".to_string())
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
// Check if nothing needs attention
|
// Check if nothing needs attention
|
||||||
if content == "HEARTBEAT_OK" || content.contains("HEARTBEAT_OK") {
|
if content == "HEARTBEAT_OK" || content.contains("HEARTBEAT_OK") {
|
||||||
return HeartbeatResult::Ok;
|
return HeartbeatResult::Ok;
|
||||||
|
|||||||
@@ -6,6 +6,7 @@
|
|||||||
//! - Tool invocation with safety
|
//! - Tool invocation with safety
|
||||||
//! - Self-repair for stuck jobs
|
//! - Self-repair for stuck jobs
|
||||||
//! - Proactive heartbeat execution
|
//! - Proactive heartbeat execution
|
||||||
|
//! - Routine-based scheduled and reactive jobs
|
||||||
//! - Turn-based session management with undo
|
//! - Turn-based session management with undo
|
||||||
//! - Context compaction for long conversations
|
//! - Context compaction for long conversations
|
||||||
|
|
||||||
@@ -14,6 +15,8 @@ pub mod compaction;
|
|||||||
pub mod context_monitor;
|
pub mod context_monitor;
|
||||||
mod heartbeat;
|
mod heartbeat;
|
||||||
mod router;
|
mod router;
|
||||||
|
pub mod routine;
|
||||||
|
pub mod routine_engine;
|
||||||
mod scheduler;
|
mod scheduler;
|
||||||
mod self_repair;
|
mod self_repair;
|
||||||
pub mod session;
|
pub mod session;
|
||||||
@@ -23,11 +26,14 @@ pub mod task;
|
|||||||
pub mod undo;
|
pub mod undo;
|
||||||
pub mod worker;
|
pub mod worker;
|
||||||
|
|
||||||
|
pub(crate) use agent_loop::truncate_for_preview;
|
||||||
pub use agent_loop::{Agent, AgentDeps};
|
pub use agent_loop::{Agent, AgentDeps};
|
||||||
pub use compaction::{CompactionResult, ContextCompactor};
|
pub use compaction::{CompactionResult, ContextCompactor};
|
||||||
pub use context_monitor::{CompactionStrategy, ContextBreakdown, ContextMonitor};
|
pub use context_monitor::{CompactionStrategy, ContextBreakdown, ContextMonitor};
|
||||||
pub use heartbeat::{HeartbeatConfig, HeartbeatResult, HeartbeatRunner, spawn_heartbeat};
|
pub use heartbeat::{HeartbeatConfig, HeartbeatResult, HeartbeatRunner, spawn_heartbeat};
|
||||||
pub use router::{MessageIntent, Router};
|
pub use router::{MessageIntent, Router};
|
||||||
|
pub use routine::{Routine, RoutineAction, RoutineRun, Trigger};
|
||||||
|
pub use routine_engine::RoutineEngine;
|
||||||
pub use scheduler::Scheduler;
|
pub use scheduler::Scheduler;
|
||||||
pub use self_repair::{BrokenTool, RepairResult, RepairTask, SelfRepair, StuckJob};
|
pub use self_repair::{BrokenTool, RepairResult, RepairTask, SelfRepair, StuckJob};
|
||||||
pub use session::{PendingApproval, PendingAuth, Session, Thread, ThreadState, Turn, TurnState};
|
pub use session::{PendingApproval, PendingAuth, Session, Thread, ThreadState, Turn, TurnState};
|
||||||
|
|||||||
@@ -0,0 +1,509 @@
|
|||||||
|
//! Core types for the routines system.
|
||||||
|
//!
|
||||||
|
//! A routine is a named, persistent, user-owned task with a trigger and an action.
|
||||||
|
//! Each routine fires independently when its trigger condition is met, with only
|
||||||
|
//! that routine's prompt and context sent to the LLM.
|
||||||
|
//!
|
||||||
|
//! ```text
|
||||||
|
//! ┌──────────┐ ┌─────────┐ ┌──────────────────┐
|
||||||
|
//! │ Trigger │────▶│ Engine │────▶│ Execution Mode │
|
||||||
|
//! │ cron/event│ │guardrail│ │lightweight│full_job│
|
||||||
|
//! │ webhook │ │ check │ └──────────────────┘
|
||||||
|
//! │ manual │ └─────────┘ │
|
||||||
|
//! └──────────┘ ▼
|
||||||
|
//! ┌──────────────┐
|
||||||
|
//! │ Notify user │
|
||||||
|
//! │ if needed │
|
||||||
|
//! └──────────────┘
|
||||||
|
//! ```
|
||||||
|
|
||||||
|
use std::collections::hash_map::DefaultHasher;
|
||||||
|
use std::hash::{Hash, Hasher};
|
||||||
|
use std::str::FromStr;
|
||||||
|
use std::time::Duration;
|
||||||
|
|
||||||
|
use chrono::{DateTime, Utc};
|
||||||
|
use serde::{Deserialize, Serialize};
|
||||||
|
use uuid::Uuid;
|
||||||
|
|
||||||
|
/// A routine is a named, persistent, user-owned task with a trigger and an action.
|
||||||
|
#[derive(Debug, Clone, Serialize, Deserialize)]
|
||||||
|
pub struct Routine {
|
||||||
|
pub id: Uuid,
|
||||||
|
pub name: String,
|
||||||
|
pub description: String,
|
||||||
|
pub user_id: String,
|
||||||
|
pub enabled: bool,
|
||||||
|
pub trigger: Trigger,
|
||||||
|
pub action: RoutineAction,
|
||||||
|
pub guardrails: RoutineGuardrails,
|
||||||
|
pub notify: NotifyConfig,
|
||||||
|
|
||||||
|
// Runtime state (DB-managed)
|
||||||
|
pub last_run_at: Option<DateTime<Utc>>,
|
||||||
|
pub next_fire_at: Option<DateTime<Utc>>,
|
||||||
|
pub run_count: u64,
|
||||||
|
pub consecutive_failures: u32,
|
||||||
|
pub state: serde_json::Value,
|
||||||
|
|
||||||
|
pub created_at: DateTime<Utc>,
|
||||||
|
pub updated_at: DateTime<Utc>,
|
||||||
|
}
|
||||||
|
|
||||||
|
/// When a routine should fire.
|
||||||
|
#[derive(Debug, Clone, Serialize, Deserialize)]
|
||||||
|
#[serde(tag = "type", rename_all = "snake_case")]
|
||||||
|
pub enum Trigger {
|
||||||
|
/// Fire on a cron schedule (e.g. "0 9 * * MON-FRI" or "every 2h").
|
||||||
|
Cron { schedule: String },
|
||||||
|
/// Fire when a channel message matches a pattern.
|
||||||
|
Event {
|
||||||
|
/// Optional channel filter (e.g. "telegram", "slack").
|
||||||
|
channel: Option<String>,
|
||||||
|
/// Regex pattern to match against message content.
|
||||||
|
pattern: String,
|
||||||
|
},
|
||||||
|
/// Fire on incoming webhook POST to /hooks/routine/{id}.
|
||||||
|
Webhook {
|
||||||
|
/// Optional webhook path suffix (defaults to routine id).
|
||||||
|
path: Option<String>,
|
||||||
|
/// Optional shared secret for HMAC validation.
|
||||||
|
secret: Option<String>,
|
||||||
|
},
|
||||||
|
/// Only fires via tool call or CLI.
|
||||||
|
Manual,
|
||||||
|
}
|
||||||
|
|
||||||
|
impl Trigger {
|
||||||
|
/// The string tag stored in the DB trigger_type column.
|
||||||
|
pub fn type_tag(&self) -> &'static str {
|
||||||
|
match self {
|
||||||
|
Trigger::Cron { .. } => "cron",
|
||||||
|
Trigger::Event { .. } => "event",
|
||||||
|
Trigger::Webhook { .. } => "webhook",
|
||||||
|
Trigger::Manual => "manual",
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Parse a trigger from its DB representation.
|
||||||
|
pub fn from_db(trigger_type: &str, config: serde_json::Value) -> Result<Self, String> {
|
||||||
|
match trigger_type {
|
||||||
|
"cron" => {
|
||||||
|
let schedule = config
|
||||||
|
.get("schedule")
|
||||||
|
.and_then(|v| v.as_str())
|
||||||
|
.ok_or("cron trigger missing 'schedule'")?
|
||||||
|
.to_string();
|
||||||
|
Ok(Trigger::Cron { schedule })
|
||||||
|
}
|
||||||
|
"event" => {
|
||||||
|
let pattern = config
|
||||||
|
.get("pattern")
|
||||||
|
.and_then(|v| v.as_str())
|
||||||
|
.ok_or("event trigger missing 'pattern'")?
|
||||||
|
.to_string();
|
||||||
|
let channel = config
|
||||||
|
.get("channel")
|
||||||
|
.and_then(|v| v.as_str())
|
||||||
|
.map(String::from);
|
||||||
|
Ok(Trigger::Event { channel, pattern })
|
||||||
|
}
|
||||||
|
"webhook" => {
|
||||||
|
let path = config
|
||||||
|
.get("path")
|
||||||
|
.and_then(|v| v.as_str())
|
||||||
|
.map(String::from);
|
||||||
|
let secret = config
|
||||||
|
.get("secret")
|
||||||
|
.and_then(|v| v.as_str())
|
||||||
|
.map(String::from);
|
||||||
|
Ok(Trigger::Webhook { path, secret })
|
||||||
|
}
|
||||||
|
"manual" => Ok(Trigger::Manual),
|
||||||
|
other => Err(format!("unknown trigger type: {other}")),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Serialize trigger-specific config to JSON for DB storage.
|
||||||
|
pub fn to_config_json(&self) -> serde_json::Value {
|
||||||
|
match self {
|
||||||
|
Trigger::Cron { schedule } => serde_json::json!({ "schedule": schedule }),
|
||||||
|
Trigger::Event { channel, pattern } => serde_json::json!({
|
||||||
|
"pattern": pattern,
|
||||||
|
"channel": channel,
|
||||||
|
}),
|
||||||
|
Trigger::Webhook { path, secret } => serde_json::json!({
|
||||||
|
"path": path,
|
||||||
|
"secret": secret,
|
||||||
|
}),
|
||||||
|
Trigger::Manual => serde_json::json!({}),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// What happens when a routine fires.
|
||||||
|
#[derive(Debug, Clone, Serialize, Deserialize)]
|
||||||
|
#[serde(tag = "type", rename_all = "snake_case")]
|
||||||
|
pub enum RoutineAction {
|
||||||
|
/// Single LLM call, no tools. Cheap and fast.
|
||||||
|
Lightweight {
|
||||||
|
/// The prompt sent to the LLM.
|
||||||
|
prompt: String,
|
||||||
|
/// Workspace paths to load as context (e.g. ["context/priorities.md"]).
|
||||||
|
#[serde(default)]
|
||||||
|
context_paths: Vec<String>,
|
||||||
|
/// Max output tokens (default: 4096).
|
||||||
|
#[serde(default = "default_max_tokens")]
|
||||||
|
max_tokens: u32,
|
||||||
|
},
|
||||||
|
/// Full multi-turn worker job with tool access.
|
||||||
|
FullJob {
|
||||||
|
/// Job title for the scheduler.
|
||||||
|
title: String,
|
||||||
|
/// Job description / initial prompt.
|
||||||
|
description: String,
|
||||||
|
/// Max reasoning iterations (default: 10).
|
||||||
|
#[serde(default = "default_max_iterations")]
|
||||||
|
max_iterations: u32,
|
||||||
|
},
|
||||||
|
}
|
||||||
|
|
||||||
|
fn default_max_tokens() -> u32 {
|
||||||
|
4096
|
||||||
|
}
|
||||||
|
|
||||||
|
fn default_max_iterations() -> u32 {
|
||||||
|
10
|
||||||
|
}
|
||||||
|
|
||||||
|
impl RoutineAction {
|
||||||
|
/// The string tag stored in the DB action_type column.
|
||||||
|
pub fn type_tag(&self) -> &'static str {
|
||||||
|
match self {
|
||||||
|
RoutineAction::Lightweight { .. } => "lightweight",
|
||||||
|
RoutineAction::FullJob { .. } => "full_job",
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Parse an action from its DB representation.
|
||||||
|
pub fn from_db(action_type: &str, config: serde_json::Value) -> Result<Self, String> {
|
||||||
|
match action_type {
|
||||||
|
"lightweight" => {
|
||||||
|
let prompt = config
|
||||||
|
.get("prompt")
|
||||||
|
.and_then(|v| v.as_str())
|
||||||
|
.ok_or("lightweight action missing 'prompt'")?
|
||||||
|
.to_string();
|
||||||
|
let context_paths = config
|
||||||
|
.get("context_paths")
|
||||||
|
.and_then(|v| v.as_array())
|
||||||
|
.map(|arr| {
|
||||||
|
arr.iter()
|
||||||
|
.filter_map(|v| v.as_str().map(String::from))
|
||||||
|
.collect()
|
||||||
|
})
|
||||||
|
.unwrap_or_default();
|
||||||
|
let max_tokens = config
|
||||||
|
.get("max_tokens")
|
||||||
|
.and_then(|v| v.as_u64())
|
||||||
|
.unwrap_or(default_max_tokens() as u64) as u32;
|
||||||
|
Ok(RoutineAction::Lightweight {
|
||||||
|
prompt,
|
||||||
|
context_paths,
|
||||||
|
max_tokens,
|
||||||
|
})
|
||||||
|
}
|
||||||
|
"full_job" => {
|
||||||
|
let title = config
|
||||||
|
.get("title")
|
||||||
|
.and_then(|v| v.as_str())
|
||||||
|
.ok_or("full_job action missing 'title'")?
|
||||||
|
.to_string();
|
||||||
|
let description = config
|
||||||
|
.get("description")
|
||||||
|
.and_then(|v| v.as_str())
|
||||||
|
.ok_or("full_job action missing 'description'")?
|
||||||
|
.to_string();
|
||||||
|
let max_iterations = config
|
||||||
|
.get("max_iterations")
|
||||||
|
.and_then(|v| v.as_u64())
|
||||||
|
.unwrap_or(default_max_iterations() as u64)
|
||||||
|
as u32;
|
||||||
|
Ok(RoutineAction::FullJob {
|
||||||
|
title,
|
||||||
|
description,
|
||||||
|
max_iterations,
|
||||||
|
})
|
||||||
|
}
|
||||||
|
other => Err(format!("unknown action type: {other}")),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Serialize action config to JSON for DB storage.
|
||||||
|
pub fn to_config_json(&self) -> serde_json::Value {
|
||||||
|
match self {
|
||||||
|
RoutineAction::Lightweight {
|
||||||
|
prompt,
|
||||||
|
context_paths,
|
||||||
|
max_tokens,
|
||||||
|
} => serde_json::json!({
|
||||||
|
"prompt": prompt,
|
||||||
|
"context_paths": context_paths,
|
||||||
|
"max_tokens": max_tokens,
|
||||||
|
}),
|
||||||
|
RoutineAction::FullJob {
|
||||||
|
title,
|
||||||
|
description,
|
||||||
|
max_iterations,
|
||||||
|
} => serde_json::json!({
|
||||||
|
"title": title,
|
||||||
|
"description": description,
|
||||||
|
"max_iterations": max_iterations,
|
||||||
|
}),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Guardrails to prevent runaway execution.
|
||||||
|
#[derive(Debug, Clone, Serialize, Deserialize)]
|
||||||
|
pub struct RoutineGuardrails {
|
||||||
|
/// Minimum time between fires.
|
||||||
|
pub cooldown: Duration,
|
||||||
|
/// Max simultaneous runs of this routine.
|
||||||
|
pub max_concurrent: u32,
|
||||||
|
/// Window for content-hash dedup (event triggers). None = no dedup.
|
||||||
|
pub dedup_window: Option<Duration>,
|
||||||
|
}
|
||||||
|
|
||||||
|
impl Default for RoutineGuardrails {
|
||||||
|
fn default() -> Self {
|
||||||
|
Self {
|
||||||
|
cooldown: Duration::from_secs(300),
|
||||||
|
max_concurrent: 1,
|
||||||
|
dedup_window: None,
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Notification preferences for a routine.
|
||||||
|
#[derive(Debug, Clone, Serialize, Deserialize)]
|
||||||
|
pub struct NotifyConfig {
|
||||||
|
/// Channel to notify on (None = default/broadcast all).
|
||||||
|
pub channel: Option<String>,
|
||||||
|
/// User to notify.
|
||||||
|
pub user: String,
|
||||||
|
/// Notify when routine produces actionable output.
|
||||||
|
pub on_attention: bool,
|
||||||
|
/// Notify when routine errors.
|
||||||
|
pub on_failure: bool,
|
||||||
|
/// Notify when routine runs with no findings.
|
||||||
|
pub on_success: bool,
|
||||||
|
}
|
||||||
|
|
||||||
|
impl Default for NotifyConfig {
|
||||||
|
fn default() -> Self {
|
||||||
|
Self {
|
||||||
|
channel: None,
|
||||||
|
user: "default".to_string(),
|
||||||
|
on_attention: true,
|
||||||
|
on_failure: true,
|
||||||
|
on_success: false,
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Status of a routine run.
|
||||||
|
#[derive(Debug, Clone, Copy, PartialEq, Eq, Serialize, Deserialize)]
|
||||||
|
#[serde(rename_all = "snake_case")]
|
||||||
|
pub enum RunStatus {
|
||||||
|
Running,
|
||||||
|
Ok,
|
||||||
|
Attention,
|
||||||
|
Failed,
|
||||||
|
}
|
||||||
|
|
||||||
|
impl std::fmt::Display for RunStatus {
|
||||||
|
fn fmt(&self, f: &mut std::fmt::Formatter<'_>) -> std::fmt::Result {
|
||||||
|
match self {
|
||||||
|
RunStatus::Running => write!(f, "running"),
|
||||||
|
RunStatus::Ok => write!(f, "ok"),
|
||||||
|
RunStatus::Attention => write!(f, "attention"),
|
||||||
|
RunStatus::Failed => write!(f, "failed"),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
impl FromStr for RunStatus {
|
||||||
|
type Err = String;
|
||||||
|
fn from_str(s: &str) -> Result<Self, Self::Err> {
|
||||||
|
match s {
|
||||||
|
"running" => Ok(RunStatus::Running),
|
||||||
|
"ok" => Ok(RunStatus::Ok),
|
||||||
|
"attention" => Ok(RunStatus::Attention),
|
||||||
|
"failed" => Ok(RunStatus::Failed),
|
||||||
|
other => Err(format!("unknown run status: {other}")),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// A single execution of a routine.
|
||||||
|
#[derive(Debug, Clone, Serialize, Deserialize)]
|
||||||
|
pub struct RoutineRun {
|
||||||
|
pub id: Uuid,
|
||||||
|
pub routine_id: Uuid,
|
||||||
|
pub trigger_type: String,
|
||||||
|
pub trigger_detail: Option<String>,
|
||||||
|
pub started_at: DateTime<Utc>,
|
||||||
|
pub completed_at: Option<DateTime<Utc>>,
|
||||||
|
pub status: RunStatus,
|
||||||
|
pub result_summary: Option<String>,
|
||||||
|
pub tokens_used: Option<i32>,
|
||||||
|
pub job_id: Option<Uuid>,
|
||||||
|
pub created_at: DateTime<Utc>,
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Compute a content hash for event dedup.
|
||||||
|
pub fn content_hash(content: &str) -> u64 {
|
||||||
|
let mut hasher = DefaultHasher::new();
|
||||||
|
content.hash(&mut hasher);
|
||||||
|
hasher.finish()
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Parse a cron expression and compute the next fire time from now.
|
||||||
|
pub fn next_cron_fire(schedule: &str) -> Result<Option<DateTime<Utc>>, String> {
|
||||||
|
let cron_schedule =
|
||||||
|
cron::Schedule::from_str(schedule).map_err(|e| format!("invalid cron: {e}"))?;
|
||||||
|
Ok(cron_schedule.upcoming(Utc).next())
|
||||||
|
}
|
||||||
|
|
||||||
|
#[cfg(test)]
|
||||||
|
mod tests {
|
||||||
|
use crate::agent::routine::{
|
||||||
|
RoutineAction, RoutineGuardrails, RunStatus, Trigger, content_hash, next_cron_fire,
|
||||||
|
};
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_trigger_roundtrip() {
|
||||||
|
let trigger = Trigger::Cron {
|
||||||
|
schedule: "0 9 * * MON-FRI".to_string(),
|
||||||
|
};
|
||||||
|
let json = trigger.to_config_json();
|
||||||
|
let parsed = Trigger::from_db("cron", json).expect("parse cron");
|
||||||
|
assert!(matches!(parsed, Trigger::Cron { schedule } if schedule == "0 9 * * MON-FRI"));
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_event_trigger_roundtrip() {
|
||||||
|
let trigger = Trigger::Event {
|
||||||
|
channel: Some("telegram".to_string()),
|
||||||
|
pattern: r"deploy\s+\w+".to_string(),
|
||||||
|
};
|
||||||
|
let json = trigger.to_config_json();
|
||||||
|
let parsed = Trigger::from_db("event", json).expect("parse event");
|
||||||
|
assert!(matches!(parsed, Trigger::Event { channel, pattern }
|
||||||
|
if channel == Some("telegram".to_string()) && pattern == r"deploy\s+\w+"));
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_action_lightweight_roundtrip() {
|
||||||
|
let action = RoutineAction::Lightweight {
|
||||||
|
prompt: "Check PRs".to_string(),
|
||||||
|
context_paths: vec!["context/priorities.md".to_string()],
|
||||||
|
max_tokens: 2048,
|
||||||
|
};
|
||||||
|
let json = action.to_config_json();
|
||||||
|
let parsed = RoutineAction::from_db("lightweight", json).expect("parse lightweight");
|
||||||
|
assert!(
|
||||||
|
matches!(parsed, RoutineAction::Lightweight { prompt, context_paths, max_tokens }
|
||||||
|
if prompt == "Check PRs" && context_paths.len() == 1 && max_tokens == 2048)
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_action_full_job_roundtrip() {
|
||||||
|
let action = RoutineAction::FullJob {
|
||||||
|
title: "Deploy review".to_string(),
|
||||||
|
description: "Review and deploy pending changes".to_string(),
|
||||||
|
max_iterations: 5,
|
||||||
|
};
|
||||||
|
let json = action.to_config_json();
|
||||||
|
let parsed = RoutineAction::from_db("full_job", json).expect("parse full_job");
|
||||||
|
assert!(
|
||||||
|
matches!(parsed, RoutineAction::FullJob { title, max_iterations, .. }
|
||||||
|
if title == "Deploy review" && max_iterations == 5)
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_run_status_display_parse() {
|
||||||
|
for status in [
|
||||||
|
RunStatus::Running,
|
||||||
|
RunStatus::Ok,
|
||||||
|
RunStatus::Attention,
|
||||||
|
RunStatus::Failed,
|
||||||
|
] {
|
||||||
|
let s = status.to_string();
|
||||||
|
let parsed: RunStatus = s.parse().expect("parse status");
|
||||||
|
assert_eq!(parsed, status);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_content_hash_deterministic() {
|
||||||
|
let h1 = content_hash("deploy production");
|
||||||
|
let h2 = content_hash("deploy production");
|
||||||
|
assert_eq!(h1, h2);
|
||||||
|
|
||||||
|
let h3 = content_hash("deploy staging");
|
||||||
|
assert_ne!(h1, h3);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_next_cron_fire_valid() {
|
||||||
|
// Every minute should always have a next fire
|
||||||
|
let next = next_cron_fire("* * * * * *").expect("valid cron");
|
||||||
|
assert!(next.is_some());
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_next_cron_fire_invalid() {
|
||||||
|
let result = next_cron_fire("not a cron");
|
||||||
|
assert!(result.is_err());
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_guardrails_default() {
|
||||||
|
let g = RoutineGuardrails::default();
|
||||||
|
assert_eq!(g.cooldown.as_secs(), 300);
|
||||||
|
assert_eq!(g.max_concurrent, 1);
|
||||||
|
assert!(g.dedup_window.is_none());
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_trigger_type_tag() {
|
||||||
|
assert_eq!(
|
||||||
|
Trigger::Cron {
|
||||||
|
schedule: String::new()
|
||||||
|
}
|
||||||
|
.type_tag(),
|
||||||
|
"cron"
|
||||||
|
);
|
||||||
|
assert_eq!(
|
||||||
|
Trigger::Event {
|
||||||
|
channel: None,
|
||||||
|
pattern: String::new()
|
||||||
|
}
|
||||||
|
.type_tag(),
|
||||||
|
"event"
|
||||||
|
);
|
||||||
|
assert_eq!(
|
||||||
|
Trigger::Webhook {
|
||||||
|
path: None,
|
||||||
|
secret: None
|
||||||
|
}
|
||||||
|
.type_tag(),
|
||||||
|
"webhook"
|
||||||
|
);
|
||||||
|
assert_eq!(Trigger::Manual.type_tag(), "manual");
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,601 @@
|
|||||||
|
//! Routine execution engine.
|
||||||
|
//!
|
||||||
|
//! Handles loading routines, checking triggers, enforcing guardrails,
|
||||||
|
//! and executing both lightweight (single LLM call) and full-job routines.
|
||||||
|
//!
|
||||||
|
//! The engine runs two independent loops:
|
||||||
|
//! - A **cron ticker** that polls the DB every N seconds for due cron routines
|
||||||
|
//! - An **event matcher** called synchronously from the agent main loop
|
||||||
|
//!
|
||||||
|
//! Lightweight routines execute inline (single LLM call, no scheduler slot).
|
||||||
|
//! Full-job routines are delegated to the existing `Scheduler`.
|
||||||
|
|
||||||
|
use std::sync::Arc;
|
||||||
|
use std::sync::atomic::{AtomicUsize, Ordering};
|
||||||
|
use std::time::Duration;
|
||||||
|
|
||||||
|
use chrono::Utc;
|
||||||
|
use regex::Regex;
|
||||||
|
use tokio::sync::{RwLock, mpsc};
|
||||||
|
use uuid::Uuid;
|
||||||
|
|
||||||
|
use crate::agent::routine::{
|
||||||
|
NotifyConfig, Routine, RoutineAction, RoutineRun, RunStatus, Trigger, next_cron_fire,
|
||||||
|
};
|
||||||
|
use crate::channels::{IncomingMessage, OutgoingResponse};
|
||||||
|
use crate::config::RoutineConfig;
|
||||||
|
use crate::db::Database;
|
||||||
|
use crate::llm::{ChatMessage, CompletionRequest, FinishReason, LlmProvider};
|
||||||
|
use crate::workspace::Workspace;
|
||||||
|
|
||||||
|
/// The routine execution engine.
|
||||||
|
pub struct RoutineEngine {
|
||||||
|
config: RoutineConfig,
|
||||||
|
store: Arc<dyn Database>,
|
||||||
|
llm: Arc<dyn LlmProvider>,
|
||||||
|
workspace: Arc<Workspace>,
|
||||||
|
/// Sender for notifications (routed to channel manager).
|
||||||
|
notify_tx: mpsc::Sender<OutgoingResponse>,
|
||||||
|
/// Currently running routine count (across all routines).
|
||||||
|
running_count: Arc<AtomicUsize>,
|
||||||
|
/// Compiled event regex cache: routine_id -> compiled regex.
|
||||||
|
event_cache: Arc<RwLock<Vec<(Uuid, Routine, Regex)>>>,
|
||||||
|
}
|
||||||
|
|
||||||
|
impl RoutineEngine {
|
||||||
|
pub fn new(
|
||||||
|
config: RoutineConfig,
|
||||||
|
store: Arc<dyn Database>,
|
||||||
|
llm: Arc<dyn LlmProvider>,
|
||||||
|
workspace: Arc<Workspace>,
|
||||||
|
notify_tx: mpsc::Sender<OutgoingResponse>,
|
||||||
|
) -> Self {
|
||||||
|
Self {
|
||||||
|
config,
|
||||||
|
store,
|
||||||
|
llm,
|
||||||
|
workspace,
|
||||||
|
notify_tx,
|
||||||
|
running_count: Arc::new(AtomicUsize::new(0)),
|
||||||
|
event_cache: Arc::new(RwLock::new(Vec::new())),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Refresh the in-memory event trigger cache from DB.
|
||||||
|
pub async fn refresh_event_cache(&self) {
|
||||||
|
match self.store.list_event_routines().await {
|
||||||
|
Ok(routines) => {
|
||||||
|
let mut cache = Vec::new();
|
||||||
|
for routine in routines {
|
||||||
|
if let Trigger::Event { ref pattern, .. } = routine.trigger {
|
||||||
|
match Regex::new(pattern) {
|
||||||
|
Ok(re) => cache.push((routine.id, routine.clone(), re)),
|
||||||
|
Err(e) => {
|
||||||
|
tracing::warn!(
|
||||||
|
routine = %routine.name,
|
||||||
|
"Invalid event regex '{}': {}",
|
||||||
|
pattern, e
|
||||||
|
);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
let count = cache.len();
|
||||||
|
*self.event_cache.write().await = cache;
|
||||||
|
tracing::debug!("Refreshed event cache: {} routines", count);
|
||||||
|
}
|
||||||
|
Err(e) => {
|
||||||
|
tracing::error!("Failed to refresh event cache: {}", e);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Check incoming message against event triggers. Returns number of routines fired.
|
||||||
|
///
|
||||||
|
/// Called synchronously from the main loop after handle_message(). The actual
|
||||||
|
/// execution is spawned async so this returns quickly.
|
||||||
|
pub async fn check_event_triggers(&self, message: &IncomingMessage) -> usize {
|
||||||
|
let cache = self.event_cache.read().await;
|
||||||
|
let mut fired = 0;
|
||||||
|
|
||||||
|
for (_, routine, re) in cache.iter() {
|
||||||
|
// Channel filter
|
||||||
|
if let Trigger::Event {
|
||||||
|
channel: Some(ch), ..
|
||||||
|
} = &routine.trigger
|
||||||
|
&& ch != &message.channel
|
||||||
|
{
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
|
||||||
|
// Regex match
|
||||||
|
if !re.is_match(&message.content) {
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
|
||||||
|
// Cooldown check
|
||||||
|
if !self.check_cooldown(routine) {
|
||||||
|
tracing::debug!(routine = %routine.name, "Skipped: cooldown active");
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
|
||||||
|
// Concurrent run check
|
||||||
|
if !self.check_concurrent(routine).await {
|
||||||
|
tracing::debug!(routine = %routine.name, "Skipped: max concurrent reached");
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
|
||||||
|
// Global capacity check
|
||||||
|
if self.running_count.load(Ordering::Relaxed) >= self.config.max_concurrent_routines {
|
||||||
|
tracing::warn!(routine = %routine.name, "Skipped: global max concurrent reached");
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
|
||||||
|
let detail = truncate(&message.content, 200);
|
||||||
|
self.spawn_fire(routine.clone(), "event", Some(detail));
|
||||||
|
fired += 1;
|
||||||
|
}
|
||||||
|
|
||||||
|
fired
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Check all due cron routines and fire them. Called by the cron ticker.
|
||||||
|
pub async fn check_cron_triggers(&self) {
|
||||||
|
let routines = match self.store.list_due_cron_routines().await {
|
||||||
|
Ok(r) => r,
|
||||||
|
Err(e) => {
|
||||||
|
tracing::error!("Failed to load due cron routines: {}", e);
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
|
for routine in routines {
|
||||||
|
if self.running_count.load(Ordering::Relaxed) >= self.config.max_concurrent_routines {
|
||||||
|
tracing::warn!("Global max concurrent routines reached, skipping remaining");
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
|
||||||
|
if !self.check_cooldown(&routine) {
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
|
||||||
|
if !self.check_concurrent(&routine).await {
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
|
||||||
|
let detail = if let Trigger::Cron { ref schedule } = routine.trigger {
|
||||||
|
Some(schedule.clone())
|
||||||
|
} else {
|
||||||
|
None
|
||||||
|
};
|
||||||
|
|
||||||
|
self.spawn_fire(routine, "cron", detail);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Fire a routine manually (from tool call or CLI).
|
||||||
|
pub async fn fire_manual(&self, routine_id: Uuid) -> Result<Uuid, String> {
|
||||||
|
let routine = self
|
||||||
|
.store
|
||||||
|
.get_routine(routine_id)
|
||||||
|
.await
|
||||||
|
.map_err(|e| format!("DB error: {e}"))?
|
||||||
|
.ok_or_else(|| format!("routine {routine_id} not found"))?;
|
||||||
|
|
||||||
|
if !routine.enabled {
|
||||||
|
return Err(format!("routine '{}' is disabled", routine.name));
|
||||||
|
}
|
||||||
|
|
||||||
|
if !self.check_concurrent(&routine).await {
|
||||||
|
return Err(format!(
|
||||||
|
"routine '{}' already at max concurrent runs",
|
||||||
|
routine.name
|
||||||
|
));
|
||||||
|
}
|
||||||
|
|
||||||
|
let run_id = Uuid::new_v4();
|
||||||
|
let run = RoutineRun {
|
||||||
|
id: run_id,
|
||||||
|
routine_id: routine.id,
|
||||||
|
trigger_type: "manual".to_string(),
|
||||||
|
trigger_detail: None,
|
||||||
|
started_at: Utc::now(),
|
||||||
|
completed_at: None,
|
||||||
|
status: RunStatus::Running,
|
||||||
|
result_summary: None,
|
||||||
|
tokens_used: None,
|
||||||
|
job_id: None,
|
||||||
|
created_at: Utc::now(),
|
||||||
|
};
|
||||||
|
|
||||||
|
if let Err(e) = self.store.create_routine_run(&run).await {
|
||||||
|
return Err(format!("failed to create run record: {e}"));
|
||||||
|
}
|
||||||
|
|
||||||
|
// Execute inline for manual triggers (caller wants to wait)
|
||||||
|
let engine = EngineContext {
|
||||||
|
store: self.store.clone(),
|
||||||
|
llm: self.llm.clone(),
|
||||||
|
workspace: self.workspace.clone(),
|
||||||
|
notify_tx: self.notify_tx.clone(),
|
||||||
|
running_count: self.running_count.clone(),
|
||||||
|
max_lightweight_tokens: self.config.max_lightweight_tokens,
|
||||||
|
};
|
||||||
|
|
||||||
|
tokio::spawn(async move {
|
||||||
|
execute_routine(engine, routine, run).await;
|
||||||
|
});
|
||||||
|
|
||||||
|
Ok(run_id)
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Spawn a fire in a background task.
|
||||||
|
fn spawn_fire(&self, routine: Routine, trigger_type: &str, trigger_detail: Option<String>) {
|
||||||
|
let run = RoutineRun {
|
||||||
|
id: Uuid::new_v4(),
|
||||||
|
routine_id: routine.id,
|
||||||
|
trigger_type: trigger_type.to_string(),
|
||||||
|
trigger_detail,
|
||||||
|
started_at: Utc::now(),
|
||||||
|
completed_at: None,
|
||||||
|
status: RunStatus::Running,
|
||||||
|
result_summary: None,
|
||||||
|
tokens_used: None,
|
||||||
|
job_id: None,
|
||||||
|
created_at: Utc::now(),
|
||||||
|
};
|
||||||
|
|
||||||
|
let engine = EngineContext {
|
||||||
|
store: self.store.clone(),
|
||||||
|
llm: self.llm.clone(),
|
||||||
|
workspace: self.workspace.clone(),
|
||||||
|
notify_tx: self.notify_tx.clone(),
|
||||||
|
running_count: self.running_count.clone(),
|
||||||
|
max_lightweight_tokens: self.config.max_lightweight_tokens,
|
||||||
|
};
|
||||||
|
|
||||||
|
// Record the run in DB, then spawn execution
|
||||||
|
let store = self.store.clone();
|
||||||
|
tokio::spawn(async move {
|
||||||
|
if let Err(e) = store.create_routine_run(&run).await {
|
||||||
|
tracing::error!(routine = %routine.name, "Failed to record run: {}", e);
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
execute_routine(engine, routine, run).await;
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
fn check_cooldown(&self, routine: &Routine) -> bool {
|
||||||
|
if let Some(last_run) = routine.last_run_at {
|
||||||
|
let elapsed = Utc::now().signed_duration_since(last_run);
|
||||||
|
let cooldown = chrono::Duration::from_std(routine.guardrails.cooldown)
|
||||||
|
.unwrap_or(chrono::Duration::seconds(300));
|
||||||
|
if elapsed < cooldown {
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
true
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn check_concurrent(&self, routine: &Routine) -> bool {
|
||||||
|
match self.store.count_running_routine_runs(routine.id).await {
|
||||||
|
Ok(count) => count < routine.guardrails.max_concurrent as i64,
|
||||||
|
Err(e) => {
|
||||||
|
tracing::error!(
|
||||||
|
routine = %routine.name,
|
||||||
|
"Failed to check concurrent runs: {}", e
|
||||||
|
);
|
||||||
|
false
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Shared context passed to the execution function.
|
||||||
|
struct EngineContext {
|
||||||
|
store: Arc<dyn Database>,
|
||||||
|
llm: Arc<dyn LlmProvider>,
|
||||||
|
workspace: Arc<Workspace>,
|
||||||
|
notify_tx: mpsc::Sender<OutgoingResponse>,
|
||||||
|
running_count: Arc<AtomicUsize>,
|
||||||
|
max_lightweight_tokens: u32,
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Execute a routine run. Handles both lightweight and full_job modes.
|
||||||
|
async fn execute_routine(ctx: EngineContext, routine: Routine, run: RoutineRun) {
|
||||||
|
// Increment running count (atomic: survives panics in the execution below)
|
||||||
|
ctx.running_count.fetch_add(1, Ordering::Relaxed);
|
||||||
|
|
||||||
|
let result = match &routine.action {
|
||||||
|
RoutineAction::Lightweight {
|
||||||
|
prompt,
|
||||||
|
context_paths,
|
||||||
|
max_tokens,
|
||||||
|
} => execute_lightweight(&ctx, &routine, prompt, context_paths, *max_tokens).await,
|
||||||
|
RoutineAction::FullJob { description, .. } => {
|
||||||
|
// Full job mode: for now, execute as lightweight with the description
|
||||||
|
// as prompt. Full scheduler integration will come as a follow-up.
|
||||||
|
tracing::info!(
|
||||||
|
routine = %routine.name,
|
||||||
|
"FullJob mode executing as lightweight (scheduler integration pending)"
|
||||||
|
);
|
||||||
|
execute_lightweight(&ctx, &routine, description, &[], ctx.max_lightweight_tokens).await
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
|
// Decrement running count
|
||||||
|
ctx.running_count.fetch_sub(1, Ordering::Relaxed);
|
||||||
|
|
||||||
|
// Process result
|
||||||
|
let (status, summary, tokens) = match result {
|
||||||
|
Ok(execution) => execution,
|
||||||
|
Err(e) => {
|
||||||
|
tracing::error!(routine = %routine.name, "Execution failed: {}", e);
|
||||||
|
(RunStatus::Failed, Some(e), None)
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
|
// Complete the run record
|
||||||
|
if let Err(e) = ctx
|
||||||
|
.store
|
||||||
|
.complete_routine_run(run.id, status, summary.as_deref(), tokens)
|
||||||
|
.await
|
||||||
|
{
|
||||||
|
tracing::error!(routine = %routine.name, "Failed to complete run record: {}", e);
|
||||||
|
}
|
||||||
|
|
||||||
|
// Update routine runtime state
|
||||||
|
let now = Utc::now();
|
||||||
|
let next_fire = if let Trigger::Cron { ref schedule } = routine.trigger {
|
||||||
|
next_cron_fire(schedule).unwrap_or(None)
|
||||||
|
} else {
|
||||||
|
None
|
||||||
|
};
|
||||||
|
|
||||||
|
let new_failures = if status == RunStatus::Failed {
|
||||||
|
routine.consecutive_failures + 1
|
||||||
|
} else {
|
||||||
|
0
|
||||||
|
};
|
||||||
|
|
||||||
|
if let Err(e) = ctx
|
||||||
|
.store
|
||||||
|
.update_routine_runtime(
|
||||||
|
routine.id,
|
||||||
|
now,
|
||||||
|
next_fire,
|
||||||
|
routine.run_count + 1,
|
||||||
|
new_failures,
|
||||||
|
&routine.state,
|
||||||
|
)
|
||||||
|
.await
|
||||||
|
{
|
||||||
|
tracing::error!(routine = %routine.name, "Failed to update runtime state: {}", e);
|
||||||
|
}
|
||||||
|
|
||||||
|
// Send notifications based on config
|
||||||
|
send_notification(
|
||||||
|
&ctx.notify_tx,
|
||||||
|
&routine.notify,
|
||||||
|
&routine.name,
|
||||||
|
status,
|
||||||
|
summary.as_deref(),
|
||||||
|
)
|
||||||
|
.await;
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Execute a lightweight routine (single LLM call).
|
||||||
|
async fn execute_lightweight(
|
||||||
|
ctx: &EngineContext,
|
||||||
|
routine: &Routine,
|
||||||
|
prompt: &str,
|
||||||
|
context_paths: &[String],
|
||||||
|
max_tokens: u32,
|
||||||
|
) -> Result<(RunStatus, Option<String>, Option<i32>), String> {
|
||||||
|
// Load context from workspace
|
||||||
|
let mut context_parts = Vec::new();
|
||||||
|
for path in context_paths {
|
||||||
|
match ctx.workspace.read(path).await {
|
||||||
|
Ok(doc) => {
|
||||||
|
context_parts.push(format!("## {}\n\n{}", path, doc.content));
|
||||||
|
}
|
||||||
|
Err(e) => {
|
||||||
|
tracing::debug!(
|
||||||
|
routine = %routine.name,
|
||||||
|
"Failed to read context path {}: {}", path, e
|
||||||
|
);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// Load routine state from workspace
|
||||||
|
let state_path = format!("routines/{}/state.md", routine.name);
|
||||||
|
let state_content = match ctx.workspace.read(&state_path).await {
|
||||||
|
Ok(doc) => Some(doc.content),
|
||||||
|
Err(_) => None,
|
||||||
|
};
|
||||||
|
|
||||||
|
// Build the prompt
|
||||||
|
let mut full_prompt = String::new();
|
||||||
|
full_prompt.push_str(prompt);
|
||||||
|
|
||||||
|
if !context_parts.is_empty() {
|
||||||
|
full_prompt.push_str("\n\n---\n\n# Context\n\n");
|
||||||
|
full_prompt.push_str(&context_parts.join("\n\n"));
|
||||||
|
}
|
||||||
|
|
||||||
|
if let Some(state) = &state_content {
|
||||||
|
full_prompt.push_str("\n\n---\n\n# Previous State\n\n");
|
||||||
|
full_prompt.push_str(state);
|
||||||
|
}
|
||||||
|
|
||||||
|
full_prompt.push_str(
|
||||||
|
"\n\n---\n\nIf nothing needs attention, reply EXACTLY with: ROUTINE_OK\n\
|
||||||
|
If something needs attention, provide a concise summary.",
|
||||||
|
);
|
||||||
|
|
||||||
|
// Get system prompt
|
||||||
|
let system_prompt = match ctx.workspace.system_prompt().await {
|
||||||
|
Ok(p) => p,
|
||||||
|
Err(e) => {
|
||||||
|
tracing::warn!(routine = %routine.name, "Failed to get system prompt: {}", e);
|
||||||
|
String::new()
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
|
let messages = if system_prompt.is_empty() {
|
||||||
|
vec![ChatMessage::user(&full_prompt)]
|
||||||
|
} else {
|
||||||
|
vec![
|
||||||
|
ChatMessage::system(&system_prompt),
|
||||||
|
ChatMessage::user(&full_prompt),
|
||||||
|
]
|
||||||
|
};
|
||||||
|
|
||||||
|
// Determine max_tokens from model metadata with fallback
|
||||||
|
let effective_max_tokens = match ctx.llm.model_metadata().await {
|
||||||
|
Ok(meta) => {
|
||||||
|
let from_api = meta.context_length.map(|ctx| ctx / 2).unwrap_or(max_tokens);
|
||||||
|
from_api.max(max_tokens)
|
||||||
|
}
|
||||||
|
Err(_) => max_tokens,
|
||||||
|
};
|
||||||
|
|
||||||
|
let request = CompletionRequest::new(messages)
|
||||||
|
.with_max_tokens(effective_max_tokens)
|
||||||
|
.with_temperature(0.3);
|
||||||
|
|
||||||
|
let response = ctx
|
||||||
|
.llm
|
||||||
|
.complete(request)
|
||||||
|
.await
|
||||||
|
.map_err(|e| format!("LLM call failed: {e}"))?;
|
||||||
|
|
||||||
|
let content = response.content.trim();
|
||||||
|
let tokens_used = Some((response.input_tokens + response.output_tokens) as i32);
|
||||||
|
|
||||||
|
// Empty content guard (same as heartbeat)
|
||||||
|
if content.is_empty() {
|
||||||
|
return if response.finish_reason == FinishReason::Length {
|
||||||
|
Err(
|
||||||
|
"LLM response truncated (finish_reason=length) with no content. \
|
||||||
|
Model may have exhausted token budget on reasoning."
|
||||||
|
.to_string(),
|
||||||
|
)
|
||||||
|
} else {
|
||||||
|
Err("LLM returned empty content.".to_string())
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
// Check for the "nothing to do" sentinel
|
||||||
|
if content == "ROUTINE_OK" || content.contains("ROUTINE_OK") {
|
||||||
|
return Ok((RunStatus::Ok, None, tokens_used));
|
||||||
|
}
|
||||||
|
|
||||||
|
Ok((RunStatus::Attention, Some(content.to_string()), tokens_used))
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Send a notification based on the routine's notify config and run status.
|
||||||
|
async fn send_notification(
|
||||||
|
tx: &mpsc::Sender<OutgoingResponse>,
|
||||||
|
notify: &NotifyConfig,
|
||||||
|
routine_name: &str,
|
||||||
|
status: RunStatus,
|
||||||
|
summary: Option<&str>,
|
||||||
|
) {
|
||||||
|
let should_notify = match status {
|
||||||
|
RunStatus::Ok => notify.on_success,
|
||||||
|
RunStatus::Attention => notify.on_attention,
|
||||||
|
RunStatus::Failed => notify.on_failure,
|
||||||
|
RunStatus::Running => false,
|
||||||
|
};
|
||||||
|
|
||||||
|
if !should_notify {
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
let icon = match status {
|
||||||
|
RunStatus::Ok => "✅",
|
||||||
|
RunStatus::Attention => "🔔",
|
||||||
|
RunStatus::Failed => "❌",
|
||||||
|
RunStatus::Running => "⏳",
|
||||||
|
};
|
||||||
|
|
||||||
|
let message = match summary {
|
||||||
|
Some(s) => format!("{} *Routine '{}'*: {}\n\n{}", icon, routine_name, status, s),
|
||||||
|
None => format!("{} *Routine '{}'*: {}", icon, routine_name, status),
|
||||||
|
};
|
||||||
|
|
||||||
|
let response = OutgoingResponse {
|
||||||
|
content: message,
|
||||||
|
thread_id: None,
|
||||||
|
metadata: serde_json::json!({
|
||||||
|
"source": "routine",
|
||||||
|
"routine_name": routine_name,
|
||||||
|
"status": status.to_string(),
|
||||||
|
}),
|
||||||
|
};
|
||||||
|
|
||||||
|
if let Err(e) = tx.send(response).await {
|
||||||
|
tracing::error!(routine = %routine_name, "Failed to send notification: {}", e);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Spawn the cron ticker background task.
|
||||||
|
pub fn spawn_cron_ticker(
|
||||||
|
engine: Arc<RoutineEngine>,
|
||||||
|
interval: Duration,
|
||||||
|
) -> tokio::task::JoinHandle<()> {
|
||||||
|
tokio::spawn(async move {
|
||||||
|
let mut ticker = tokio::time::interval(interval);
|
||||||
|
// Skip immediate first tick
|
||||||
|
ticker.tick().await;
|
||||||
|
|
||||||
|
loop {
|
||||||
|
ticker.tick().await;
|
||||||
|
engine.check_cron_triggers().await;
|
||||||
|
}
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
|
fn truncate(s: &str, max: usize) -> String {
|
||||||
|
if s.len() <= max {
|
||||||
|
s.to_string()
|
||||||
|
} else {
|
||||||
|
let end = crate::util::floor_char_boundary(s, max);
|
||||||
|
format!("{}...", &s[..end])
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
#[cfg(test)]
|
||||||
|
mod tests {
|
||||||
|
use crate::agent::routine::{NotifyConfig, RunStatus};
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_notification_gating() {
|
||||||
|
let config = NotifyConfig {
|
||||||
|
on_success: false,
|
||||||
|
on_failure: true,
|
||||||
|
on_attention: true,
|
||||||
|
..Default::default()
|
||||||
|
};
|
||||||
|
|
||||||
|
// on_success = false means Ok status should not notify
|
||||||
|
assert!(!config.on_success);
|
||||||
|
assert!(config.on_failure);
|
||||||
|
assert!(config.on_attention);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_run_status_icons() {
|
||||||
|
// Just verify the mapping doesn't panic
|
||||||
|
for status in [
|
||||||
|
RunStatus::Ok,
|
||||||
|
RunStatus::Attention,
|
||||||
|
RunStatus::Failed,
|
||||||
|
RunStatus::Running,
|
||||||
|
] {
|
||||||
|
let _ = status.to_string();
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
+18
-18
@@ -12,8 +12,8 @@ use crate::agent::task::{Task, TaskContext, TaskOutput};
|
|||||||
use crate::agent::worker::{Worker, WorkerDeps};
|
use crate::agent::worker::{Worker, WorkerDeps};
|
||||||
use crate::config::AgentConfig;
|
use crate::config::AgentConfig;
|
||||||
use crate::context::{ContextManager, JobContext, JobState};
|
use crate::context::{ContextManager, JobContext, JobState};
|
||||||
|
use crate::db::Database;
|
||||||
use crate::error::{Error, JobError};
|
use crate::error::{Error, JobError};
|
||||||
use crate::history::Store;
|
|
||||||
use crate::llm::LlmProvider;
|
use crate::llm::LlmProvider;
|
||||||
use crate::safety::SafetyLayer;
|
use crate::safety::SafetyLayer;
|
||||||
use crate::tools::ToolRegistry;
|
use crate::tools::ToolRegistry;
|
||||||
@@ -48,7 +48,7 @@ pub struct Scheduler {
|
|||||||
llm: Arc<dyn LlmProvider>,
|
llm: Arc<dyn LlmProvider>,
|
||||||
safety: Arc<SafetyLayer>,
|
safety: Arc<SafetyLayer>,
|
||||||
tools: Arc<ToolRegistry>,
|
tools: Arc<ToolRegistry>,
|
||||||
store: Option<Arc<Store>>,
|
store: Option<Arc<dyn Database>>,
|
||||||
/// Running jobs (main LLM-driven jobs).
|
/// Running jobs (main LLM-driven jobs).
|
||||||
jobs: Arc<RwLock<HashMap<Uuid, ScheduledJob>>>,
|
jobs: Arc<RwLock<HashMap<Uuid, ScheduledJob>>>,
|
||||||
/// Running sub-tasks (tool executions, background tasks).
|
/// Running sub-tasks (tool executions, background tasks).
|
||||||
@@ -63,7 +63,7 @@ impl Scheduler {
|
|||||||
llm: Arc<dyn LlmProvider>,
|
llm: Arc<dyn LlmProvider>,
|
||||||
safety: Arc<SafetyLayer>,
|
safety: Arc<SafetyLayer>,
|
||||||
tools: Arc<ToolRegistry>,
|
tools: Arc<ToolRegistry>,
|
||||||
store: Option<Arc<Store>>,
|
store: Option<Arc<dyn Database>>,
|
||||||
) -> Self {
|
) -> Self {
|
||||||
Self {
|
Self {
|
||||||
config,
|
config,
|
||||||
@@ -79,14 +79,16 @@ impl Scheduler {
|
|||||||
|
|
||||||
/// Schedule a job for execution.
|
/// Schedule a job for execution.
|
||||||
pub async fn schedule(&self, job_id: Uuid) -> Result<(), JobError> {
|
pub async fn schedule(&self, job_id: Uuid) -> Result<(), JobError> {
|
||||||
// Check if already scheduled
|
// Hold write lock for the entire check-insert sequence to prevent
|
||||||
if self.jobs.read().await.contains_key(&job_id) {
|
// TOCTOU races where two concurrent calls both pass the checks.
|
||||||
|
{
|
||||||
|
let mut jobs = self.jobs.write().await;
|
||||||
|
|
||||||
|
if jobs.contains_key(&job_id) {
|
||||||
return Ok(());
|
return Ok(());
|
||||||
}
|
}
|
||||||
|
|
||||||
// Check capacity
|
if jobs.len() >= self.config.max_parallel_jobs {
|
||||||
let current_count = self.jobs.read().await.len();
|
|
||||||
if current_count >= self.config.max_parallel_jobs {
|
|
||||||
return Err(JobError::MaxJobsExceeded {
|
return Err(JobError::MaxJobsExceeded {
|
||||||
max: self.config.max_parallel_jobs,
|
max: self.config.max_parallel_jobs,
|
||||||
});
|
});
|
||||||
@@ -131,11 +133,9 @@ impl Scheduler {
|
|||||||
// Start the worker
|
// Start the worker
|
||||||
let _ = tx.send(WorkerMessage::Start).await;
|
let _ = tx.send(WorkerMessage::Start).await;
|
||||||
|
|
||||||
// Store the scheduled job
|
// Insert while still holding the write lock
|
||||||
self.jobs
|
jobs.insert(job_id, ScheduledJob { handle, tx });
|
||||||
.write()
|
}
|
||||||
.await
|
|
||||||
.insert(job_id, ScheduledJob { handle, tx });
|
|
||||||
|
|
||||||
// Cleanup task for this job to avoid capacity leaks
|
// Cleanup task for this job to avoid capacity leaks
|
||||||
let jobs = Arc::clone(&self.jobs);
|
let jobs = Arc::clone(&self.jobs);
|
||||||
@@ -373,15 +373,15 @@ impl Scheduler {
|
|||||||
.into());
|
.into());
|
||||||
}
|
}
|
||||||
|
|
||||||
// Execute with timeout
|
// Execute with per-tool timeout
|
||||||
let result = tokio::time::timeout(Duration::from_secs(60), async {
|
let tool_timeout = tool.execution_timeout();
|
||||||
tool.execute(params, &job_ctx).await
|
let result =
|
||||||
})
|
tokio::time::timeout(tool_timeout, async { tool.execute(params, &job_ctx).await })
|
||||||
.await
|
.await
|
||||||
.map_err(|_| {
|
.map_err(|_| {
|
||||||
Error::Tool(crate::error::ToolError::Timeout {
|
Error::Tool(crate::error::ToolError::Timeout {
|
||||||
name: tool_name.to_string(),
|
name: tool_name.to_string(),
|
||||||
timeout: Duration::from_secs(60),
|
timeout: tool_timeout,
|
||||||
})
|
})
|
||||||
})?
|
})?
|
||||||
.map_err(|e| {
|
.map_err(|e| {
|
||||||
|
|||||||
@@ -8,8 +8,8 @@ use chrono::{DateTime, Utc};
|
|||||||
use uuid::Uuid;
|
use uuid::Uuid;
|
||||||
|
|
||||||
use crate::context::{ContextManager, JobState};
|
use crate::context::{ContextManager, JobState};
|
||||||
|
use crate::db::Database;
|
||||||
use crate::error::RepairError;
|
use crate::error::RepairError;
|
||||||
use crate::history::Store;
|
|
||||||
use crate::tools::{BuildRequirement, Language, SoftwareBuilder, SoftwareType, ToolRegistry};
|
use crate::tools::{BuildRequirement, Language, SoftwareBuilder, SoftwareType, ToolRegistry};
|
||||||
|
|
||||||
/// A job that has been detected as stuck.
|
/// A job that has been detected as stuck.
|
||||||
@@ -69,7 +69,7 @@ pub struct DefaultSelfRepair {
|
|||||||
#[allow(dead_code)] // Will be used for time-based stuck detection
|
#[allow(dead_code)] // Will be used for time-based stuck detection
|
||||||
stuck_threshold: Duration,
|
stuck_threshold: Duration,
|
||||||
max_repair_attempts: u32,
|
max_repair_attempts: u32,
|
||||||
store: Option<Arc<Store>>,
|
store: Option<Arc<dyn Database>>,
|
||||||
builder: Option<Arc<dyn SoftwareBuilder>>,
|
builder: Option<Arc<dyn SoftwareBuilder>>,
|
||||||
#[allow(dead_code)] // Will be used for tool hot-reload after repair
|
#[allow(dead_code)] // Will be used for tool hot-reload after repair
|
||||||
tools: Option<Arc<ToolRegistry>>,
|
tools: Option<Arc<ToolRegistry>>,
|
||||||
@@ -94,7 +94,7 @@ impl DefaultSelfRepair {
|
|||||||
|
|
||||||
/// Add a Store for tool failure tracking.
|
/// Add a Store for tool failure tracking.
|
||||||
#[allow(dead_code)] // Public API for configuring repair with persistence
|
#[allow(dead_code)] // Public API for configuring repair with persistence
|
||||||
pub fn with_store(mut self, store: Arc<Store>) -> Self {
|
pub fn with_store(mut self, store: Arc<dyn Database>) -> Self {
|
||||||
self.store = Some(store);
|
self.store = Some(store);
|
||||||
self
|
self
|
||||||
}
|
}
|
||||||
@@ -119,8 +119,9 @@ impl SelfRepair for DefaultSelfRepair {
|
|||||||
let mut stuck_jobs = Vec::new();
|
let mut stuck_jobs = Vec::new();
|
||||||
|
|
||||||
for job_id in stuck_ids {
|
for job_id in stuck_ids {
|
||||||
if let Ok(ctx) = self.context_manager.get_context(job_id).await {
|
if let Ok(ctx) = self.context_manager.get_context(job_id).await
|
||||||
if ctx.state == JobState::Stuck {
|
&& ctx.state == JobState::Stuck
|
||||||
|
{
|
||||||
let stuck_duration = ctx
|
let stuck_duration = ctx
|
||||||
.started_at
|
.started_at
|
||||||
.map(|start| {
|
.map(|start| {
|
||||||
@@ -139,7 +140,6 @@ impl SelfRepair for DefaultSelfRepair {
|
|||||||
});
|
});
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
|
||||||
|
|
||||||
stuck_jobs
|
stuck_jobs
|
||||||
}
|
}
|
||||||
|
|||||||
+407
-3
@@ -173,6 +173,10 @@ pub struct Thread {
|
|||||||
/// Pending auth token request (thread is in auth mode).
|
/// Pending auth token request (thread is in auth mode).
|
||||||
#[serde(default)]
|
#[serde(default)]
|
||||||
pub pending_auth: Option<PendingAuth>,
|
pub pending_auth: Option<PendingAuth>,
|
||||||
|
/// Last NEAR AI response ID for response chaining. Persisted to DB
|
||||||
|
/// metadata so we can resume chaining across restarts.
|
||||||
|
#[serde(default)]
|
||||||
|
pub last_response_id: Option<String>,
|
||||||
}
|
}
|
||||||
|
|
||||||
impl Thread {
|
impl Thread {
|
||||||
@@ -189,6 +193,24 @@ impl Thread {
|
|||||||
metadata: serde_json::Value::Null,
|
metadata: serde_json::Value::Null,
|
||||||
pending_approval: None,
|
pending_approval: None,
|
||||||
pending_auth: None,
|
pending_auth: None,
|
||||||
|
last_response_id: None,
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Create a thread with a specific ID (for DB hydration).
|
||||||
|
pub fn with_id(id: Uuid, session_id: Uuid) -> Self {
|
||||||
|
let now = Utc::now();
|
||||||
|
Self {
|
||||||
|
id,
|
||||||
|
session_id,
|
||||||
|
state: ThreadState::Idle,
|
||||||
|
turns: Vec::new(),
|
||||||
|
created_at: now,
|
||||||
|
updated_at: now,
|
||||||
|
metadata: serde_json::Value::Null,
|
||||||
|
pending_approval: None,
|
||||||
|
pending_auth: None,
|
||||||
|
last_response_id: None,
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -324,12 +346,12 @@ impl Thread {
|
|||||||
let mut turn = Turn::new(turn_number, &msg.content);
|
let mut turn = Turn::new(turn_number, &msg.content);
|
||||||
|
|
||||||
// Check if next is assistant response
|
// Check if next is assistant response
|
||||||
if let Some(next) = iter.peek() {
|
if let Some(next) = iter.peek()
|
||||||
if next.role == crate::llm::Role::Assistant {
|
&& next.role == crate::llm::Role::Assistant
|
||||||
|
{
|
||||||
let response = iter.next().expect("peeked");
|
let response = iter.next().expect("peeked");
|
||||||
turn.complete(&response.content);
|
turn.complete(&response.content);
|
||||||
}
|
}
|
||||||
}
|
|
||||||
|
|
||||||
self.turns.push(turn);
|
self.turns.push(turn);
|
||||||
turn_number += 1;
|
turn_number += 1;
|
||||||
@@ -593,4 +615,386 @@ mod tests {
|
|||||||
let restored: Thread = serde_json::from_str(&json).expect("should deserialize");
|
let restored: Thread = serde_json::from_str(&json).expect("should deserialize");
|
||||||
assert!(restored.pending_auth.is_none());
|
assert!(restored.pending_auth.is_none());
|
||||||
}
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_thread_with_id() {
|
||||||
|
let specific_id = Uuid::new_v4();
|
||||||
|
let session_id = Uuid::new_v4();
|
||||||
|
let thread = Thread::with_id(specific_id, session_id);
|
||||||
|
|
||||||
|
assert_eq!(thread.id, specific_id);
|
||||||
|
assert_eq!(thread.session_id, session_id);
|
||||||
|
assert_eq!(thread.state, ThreadState::Idle);
|
||||||
|
assert!(thread.turns.is_empty());
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_thread_with_id_restore_messages() {
|
||||||
|
let thread_id = Uuid::new_v4();
|
||||||
|
let session_id = Uuid::new_v4();
|
||||||
|
let mut thread = Thread::with_id(thread_id, session_id);
|
||||||
|
|
||||||
|
let messages = vec![
|
||||||
|
ChatMessage::user("Hello from DB"),
|
||||||
|
ChatMessage::assistant("Restored response"),
|
||||||
|
];
|
||||||
|
thread.restore_from_messages(messages);
|
||||||
|
|
||||||
|
assert_eq!(thread.id, thread_id);
|
||||||
|
assert_eq!(thread.turns.len(), 1);
|
||||||
|
assert_eq!(thread.turns[0].user_input, "Hello from DB");
|
||||||
|
assert_eq!(
|
||||||
|
thread.turns[0].response,
|
||||||
|
Some("Restored response".to_string())
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_restore_from_messages_empty() {
|
||||||
|
let mut thread = Thread::new(Uuid::new_v4());
|
||||||
|
|
||||||
|
// Add a turn first, then restore with empty vec
|
||||||
|
thread.start_turn("hello");
|
||||||
|
thread.complete_turn("hi");
|
||||||
|
assert_eq!(thread.turns.len(), 1);
|
||||||
|
|
||||||
|
thread.restore_from_messages(Vec::new());
|
||||||
|
|
||||||
|
// Should clear all turns and stay idle
|
||||||
|
assert!(thread.turns.is_empty());
|
||||||
|
assert_eq!(thread.state, ThreadState::Idle);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_restore_from_messages_only_assistant_messages() {
|
||||||
|
let mut thread = Thread::new(Uuid::new_v4());
|
||||||
|
|
||||||
|
// Only assistant messages (no user messages to anchor turns)
|
||||||
|
let messages = vec![
|
||||||
|
ChatMessage::assistant("I'm here"),
|
||||||
|
ChatMessage::assistant("Still here"),
|
||||||
|
];
|
||||||
|
|
||||||
|
thread.restore_from_messages(messages);
|
||||||
|
|
||||||
|
// Assistant-only messages have no user turn to attach to, so
|
||||||
|
// they should be skipped entirely.
|
||||||
|
assert!(thread.turns.is_empty());
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_restore_from_messages_multiple_user_messages_in_a_row() {
|
||||||
|
let mut thread = Thread::new(Uuid::new_v4());
|
||||||
|
|
||||||
|
// Two user messages with no assistant response between them
|
||||||
|
let messages = vec![
|
||||||
|
ChatMessage::user("first"),
|
||||||
|
ChatMessage::user("second"),
|
||||||
|
ChatMessage::assistant("reply to second"),
|
||||||
|
];
|
||||||
|
|
||||||
|
thread.restore_from_messages(messages);
|
||||||
|
|
||||||
|
// First user message becomes a turn with no response,
|
||||||
|
// second user message pairs with the assistant response.
|
||||||
|
assert_eq!(thread.turns.len(), 2);
|
||||||
|
assert_eq!(thread.turns[0].user_input, "first");
|
||||||
|
assert!(thread.turns[0].response.is_none());
|
||||||
|
assert_eq!(thread.turns[1].user_input, "second");
|
||||||
|
assert_eq!(
|
||||||
|
thread.turns[1].response,
|
||||||
|
Some("reply to second".to_string())
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_thread_switch() {
|
||||||
|
let mut session = Session::new("user-1");
|
||||||
|
|
||||||
|
let t1_id = session.create_thread().id;
|
||||||
|
let t2_id = session.create_thread().id;
|
||||||
|
|
||||||
|
// After creating two threads, active should be the last one
|
||||||
|
assert_eq!(session.active_thread, Some(t2_id));
|
||||||
|
|
||||||
|
// Switch back to the first
|
||||||
|
assert!(session.switch_thread(t1_id));
|
||||||
|
assert_eq!(session.active_thread, Some(t1_id));
|
||||||
|
|
||||||
|
// Switching to a nonexistent thread should fail
|
||||||
|
let fake_id = Uuid::new_v4();
|
||||||
|
assert!(!session.switch_thread(fake_id));
|
||||||
|
// Active thread should remain unchanged
|
||||||
|
assert_eq!(session.active_thread, Some(t1_id));
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_get_or_create_thread_idempotent() {
|
||||||
|
let mut session = Session::new("user-1");
|
||||||
|
|
||||||
|
let tid1 = session.get_or_create_thread().id;
|
||||||
|
let tid2 = session.get_or_create_thread().id;
|
||||||
|
|
||||||
|
// Should return the same thread (not create a new one each time)
|
||||||
|
assert_eq!(tid1, tid2);
|
||||||
|
assert_eq!(session.threads.len(), 1);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_truncate_turns() {
|
||||||
|
let mut thread = Thread::new(Uuid::new_v4());
|
||||||
|
|
||||||
|
for i in 0..5 {
|
||||||
|
thread.start_turn(format!("msg-{}", i));
|
||||||
|
thread.complete_turn(format!("resp-{}", i));
|
||||||
|
}
|
||||||
|
assert_eq!(thread.turns.len(), 5);
|
||||||
|
|
||||||
|
thread.truncate_turns(3);
|
||||||
|
assert_eq!(thread.turns.len(), 3);
|
||||||
|
|
||||||
|
// Should keep the most recent turns
|
||||||
|
assert_eq!(thread.turns[0].user_input, "msg-2");
|
||||||
|
assert_eq!(thread.turns[1].user_input, "msg-3");
|
||||||
|
assert_eq!(thread.turns[2].user_input, "msg-4");
|
||||||
|
|
||||||
|
// Turn numbers should be re-indexed
|
||||||
|
assert_eq!(thread.turns[0].turn_number, 0);
|
||||||
|
assert_eq!(thread.turns[1].turn_number, 1);
|
||||||
|
assert_eq!(thread.turns[2].turn_number, 2);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_truncate_turns_noop_when_fewer() {
|
||||||
|
let mut thread = Thread::new(Uuid::new_v4());
|
||||||
|
|
||||||
|
thread.start_turn("only one");
|
||||||
|
thread.complete_turn("response");
|
||||||
|
|
||||||
|
thread.truncate_turns(10);
|
||||||
|
assert_eq!(thread.turns.len(), 1);
|
||||||
|
assert_eq!(thread.turns[0].user_input, "only one");
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_thread_interrupt_and_resume() {
|
||||||
|
let mut thread = Thread::new(Uuid::new_v4());
|
||||||
|
|
||||||
|
thread.start_turn("do something");
|
||||||
|
assert_eq!(thread.state, ThreadState::Processing);
|
||||||
|
|
||||||
|
thread.interrupt();
|
||||||
|
assert_eq!(thread.state, ThreadState::Interrupted);
|
||||||
|
|
||||||
|
let last_turn = thread.last_turn().unwrap();
|
||||||
|
assert_eq!(last_turn.state, TurnState::Interrupted);
|
||||||
|
assert!(last_turn.completed_at.is_some());
|
||||||
|
|
||||||
|
thread.resume();
|
||||||
|
assert_eq!(thread.state, ThreadState::Idle);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_resume_only_from_interrupted() {
|
||||||
|
let mut thread = Thread::new(Uuid::new_v4());
|
||||||
|
|
||||||
|
// Idle thread: resume should be a no-op
|
||||||
|
assert_eq!(thread.state, ThreadState::Idle);
|
||||||
|
thread.resume();
|
||||||
|
assert_eq!(thread.state, ThreadState::Idle);
|
||||||
|
|
||||||
|
// Processing thread: resume should not change state
|
||||||
|
thread.start_turn("work");
|
||||||
|
assert_eq!(thread.state, ThreadState::Processing);
|
||||||
|
thread.resume();
|
||||||
|
assert_eq!(thread.state, ThreadState::Processing);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_turn_fail() {
|
||||||
|
let mut thread = Thread::new(Uuid::new_v4());
|
||||||
|
|
||||||
|
thread.start_turn("risky operation");
|
||||||
|
thread.fail_turn("connection timed out");
|
||||||
|
|
||||||
|
assert_eq!(thread.state, ThreadState::Idle);
|
||||||
|
|
||||||
|
let turn = thread.last_turn().unwrap();
|
||||||
|
assert_eq!(turn.state, TurnState::Failed);
|
||||||
|
assert_eq!(turn.error, Some("connection timed out".to_string()));
|
||||||
|
assert!(turn.response.is_none());
|
||||||
|
assert!(turn.completed_at.is_some());
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_messages_with_incomplete_last_turn() {
|
||||||
|
let mut thread = Thread::new(Uuid::new_v4());
|
||||||
|
|
||||||
|
thread.start_turn("first");
|
||||||
|
thread.complete_turn("first reply");
|
||||||
|
thread.start_turn("second (in progress)");
|
||||||
|
|
||||||
|
let messages = thread.messages();
|
||||||
|
// Should have 3 messages: user, assistant, user (no assistant for in-progress)
|
||||||
|
assert_eq!(messages.len(), 3);
|
||||||
|
assert_eq!(messages[0].content, "first");
|
||||||
|
assert_eq!(messages[1].content, "first reply");
|
||||||
|
assert_eq!(messages[2].content, "second (in progress)");
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_thread_serialization_round_trip() {
|
||||||
|
let mut thread = Thread::new(Uuid::new_v4());
|
||||||
|
|
||||||
|
thread.start_turn("hello");
|
||||||
|
thread.complete_turn("world");
|
||||||
|
thread.last_response_id = Some("resp_abc123".to_string());
|
||||||
|
|
||||||
|
let json = serde_json::to_string(&thread).unwrap();
|
||||||
|
let restored: Thread = serde_json::from_str(&json).unwrap();
|
||||||
|
|
||||||
|
assert_eq!(restored.id, thread.id);
|
||||||
|
assert_eq!(restored.session_id, thread.session_id);
|
||||||
|
assert_eq!(restored.turns.len(), 1);
|
||||||
|
assert_eq!(restored.turns[0].user_input, "hello");
|
||||||
|
assert_eq!(restored.turns[0].response, Some("world".to_string()));
|
||||||
|
assert_eq!(restored.last_response_id, Some("resp_abc123".to_string()));
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_session_serialization_round_trip() {
|
||||||
|
let mut session = Session::new("user-ser");
|
||||||
|
session.create_thread();
|
||||||
|
session.auto_approve_tool("echo");
|
||||||
|
|
||||||
|
let json = serde_json::to_string(&session).unwrap();
|
||||||
|
let restored: Session = serde_json::from_str(&json).unwrap();
|
||||||
|
|
||||||
|
assert_eq!(restored.user_id, "user-ser");
|
||||||
|
assert_eq!(restored.threads.len(), 1);
|
||||||
|
assert!(restored.is_tool_auto_approved("echo"));
|
||||||
|
assert!(!restored.is_tool_auto_approved("shell"));
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_auto_approved_tools() {
|
||||||
|
let mut session = Session::new("user-1");
|
||||||
|
|
||||||
|
assert!(!session.is_tool_auto_approved("shell"));
|
||||||
|
session.auto_approve_tool("shell");
|
||||||
|
assert!(session.is_tool_auto_approved("shell"));
|
||||||
|
|
||||||
|
// Idempotent
|
||||||
|
session.auto_approve_tool("shell");
|
||||||
|
assert_eq!(session.auto_approved_tools.len(), 1);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_turn_tool_call_error() {
|
||||||
|
let mut turn = Turn::new(0, "test");
|
||||||
|
turn.record_tool_call("http", serde_json::json!({"url": "example.com"}));
|
||||||
|
turn.record_tool_error("timeout");
|
||||||
|
|
||||||
|
assert_eq!(turn.tool_calls.len(), 1);
|
||||||
|
assert_eq!(turn.tool_calls[0].error, Some("timeout".to_string()));
|
||||||
|
assert!(turn.tool_calls[0].result.is_none());
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_turn_number_increments() {
|
||||||
|
let mut thread = Thread::new(Uuid::new_v4());
|
||||||
|
|
||||||
|
// Before any turns, turn_number() is 1 (1-indexed for display)
|
||||||
|
assert_eq!(thread.turn_number(), 1);
|
||||||
|
|
||||||
|
thread.start_turn("first");
|
||||||
|
thread.complete_turn("done");
|
||||||
|
assert_eq!(thread.turn_number(), 2);
|
||||||
|
|
||||||
|
thread.start_turn("second");
|
||||||
|
assert_eq!(thread.turn_number(), 3);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_complete_turn_on_empty_thread() {
|
||||||
|
let mut thread = Thread::new(Uuid::new_v4());
|
||||||
|
|
||||||
|
// Completing a turn when there are no turns should be a safe no-op
|
||||||
|
thread.complete_turn("phantom response");
|
||||||
|
assert_eq!(thread.state, ThreadState::Idle);
|
||||||
|
assert!(thread.turns.is_empty());
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_fail_turn_on_empty_thread() {
|
||||||
|
let mut thread = Thread::new(Uuid::new_v4());
|
||||||
|
|
||||||
|
// Failing a turn when there are no turns should be a safe no-op
|
||||||
|
thread.fail_turn("phantom error");
|
||||||
|
assert_eq!(thread.state, ThreadState::Idle);
|
||||||
|
assert!(thread.turns.is_empty());
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_pending_approval_flow() {
|
||||||
|
let mut thread = Thread::new(Uuid::new_v4());
|
||||||
|
|
||||||
|
let approval = PendingApproval {
|
||||||
|
request_id: Uuid::new_v4(),
|
||||||
|
tool_name: "shell".to_string(),
|
||||||
|
parameters: serde_json::json!({"command": "rm -rf /"}),
|
||||||
|
description: "dangerous command".to_string(),
|
||||||
|
tool_call_id: "call_123".to_string(),
|
||||||
|
context_messages: vec![ChatMessage::user("do it")],
|
||||||
|
};
|
||||||
|
|
||||||
|
thread.await_approval(approval);
|
||||||
|
assert_eq!(thread.state, ThreadState::AwaitingApproval);
|
||||||
|
assert!(thread.pending_approval.is_some());
|
||||||
|
|
||||||
|
let taken = thread.take_pending_approval();
|
||||||
|
assert!(taken.is_some());
|
||||||
|
assert_eq!(taken.unwrap().tool_name, "shell");
|
||||||
|
assert!(thread.pending_approval.is_none());
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_clear_pending_approval() {
|
||||||
|
let mut thread = Thread::new(Uuid::new_v4());
|
||||||
|
|
||||||
|
let approval = PendingApproval {
|
||||||
|
request_id: Uuid::new_v4(),
|
||||||
|
tool_name: "http".to_string(),
|
||||||
|
parameters: serde_json::json!({}),
|
||||||
|
description: "test".to_string(),
|
||||||
|
tool_call_id: "call_456".to_string(),
|
||||||
|
context_messages: vec![],
|
||||||
|
};
|
||||||
|
|
||||||
|
thread.await_approval(approval);
|
||||||
|
thread.clear_pending_approval();
|
||||||
|
|
||||||
|
assert_eq!(thread.state, ThreadState::Idle);
|
||||||
|
assert!(thread.pending_approval.is_none());
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_active_thread_accessors() {
|
||||||
|
let mut session = Session::new("user-1");
|
||||||
|
|
||||||
|
assert!(session.active_thread().is_none());
|
||||||
|
assert!(session.active_thread_mut().is_none());
|
||||||
|
|
||||||
|
let tid = session.create_thread().id;
|
||||||
|
|
||||||
|
assert!(session.active_thread().is_some());
|
||||||
|
assert_eq!(session.active_thread().unwrap().id, tid);
|
||||||
|
|
||||||
|
// Mutably modify through accessor
|
||||||
|
session.active_thread_mut().unwrap().start_turn("test");
|
||||||
|
assert_eq!(
|
||||||
|
session.active_thread().unwrap().state,
|
||||||
|
ThreadState::Processing
|
||||||
|
);
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -110,6 +110,41 @@ impl SessionManager {
|
|||||||
(session, thread_id)
|
(session, thread_id)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/// Register a hydrated thread so subsequent `resolve_thread` calls find it.
|
||||||
|
///
|
||||||
|
/// Inserts into the thread_map and creates an undo manager for the thread.
|
||||||
|
pub async fn register_thread(
|
||||||
|
&self,
|
||||||
|
user_id: &str,
|
||||||
|
channel: &str,
|
||||||
|
thread_id: Uuid,
|
||||||
|
session: Arc<Mutex<Session>>,
|
||||||
|
) {
|
||||||
|
let key = ThreadKey {
|
||||||
|
user_id: user_id.to_string(),
|
||||||
|
channel: channel.to_string(),
|
||||||
|
external_thread_id: Some(thread_id.to_string()),
|
||||||
|
};
|
||||||
|
|
||||||
|
{
|
||||||
|
let mut thread_map = self.thread_map.write().await;
|
||||||
|
thread_map.insert(key, thread_id);
|
||||||
|
}
|
||||||
|
|
||||||
|
{
|
||||||
|
let mut undo_managers = self.undo_managers.write().await;
|
||||||
|
undo_managers
|
||||||
|
.entry(thread_id)
|
||||||
|
.or_insert_with(|| Arc::new(Mutex::new(UndoManager::new())));
|
||||||
|
}
|
||||||
|
|
||||||
|
// Ensure the session is tracked
|
||||||
|
{
|
||||||
|
let mut sessions = self.sessions.write().await;
|
||||||
|
sessions.entry(user_id.to_string()).or_insert(session);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
/// Get undo manager for a thread.
|
/// Get undo manager for a thread.
|
||||||
pub async fn get_undo_manager(&self, thread_id: Uuid) -> Arc<Mutex<UndoManager>> {
|
pub async fn get_undo_manager(&self, thread_id: Uuid) -> Arc<Mutex<UndoManager>> {
|
||||||
// Fast path
|
// Fast path
|
||||||
@@ -164,13 +199,13 @@ impl SessionManager {
|
|||||||
{
|
{
|
||||||
let sessions = self.sessions.read().await;
|
let sessions = self.sessions.read().await;
|
||||||
for user_id in &stale_users {
|
for user_id in &stale_users {
|
||||||
if let Some(session) = sessions.get(user_id) {
|
if let Some(session) = sessions.get(user_id)
|
||||||
if let Ok(sess) = session.try_lock() {
|
&& let Ok(sess) = session.try_lock()
|
||||||
|
{
|
||||||
stale_thread_ids.extend(sess.threads.keys());
|
stale_thread_ids.extend(sess.threads.keys());
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
|
||||||
|
|
||||||
// Remove sessions
|
// Remove sessions
|
||||||
let count = {
|
let count = {
|
||||||
@@ -296,4 +331,344 @@ mod tests {
|
|||||||
.await;
|
.await;
|
||||||
assert_eq!(pruned, 0);
|
assert_eq!(pruned, 0);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
#[tokio::test]
|
||||||
|
async fn test_register_thread() {
|
||||||
|
use crate::agent::session::{Session, Thread};
|
||||||
|
|
||||||
|
let manager = SessionManager::new();
|
||||||
|
let thread_id = Uuid::new_v4();
|
||||||
|
|
||||||
|
// Create a session with a hydrated thread
|
||||||
|
let session = Arc::new(Mutex::new(Session::new("user-hydrate")));
|
||||||
|
{
|
||||||
|
let mut sess = session.lock().await;
|
||||||
|
let thread = Thread::with_id(thread_id, sess.id);
|
||||||
|
sess.threads.insert(thread_id, thread);
|
||||||
|
sess.active_thread = Some(thread_id);
|
||||||
|
}
|
||||||
|
|
||||||
|
// Register the thread
|
||||||
|
manager
|
||||||
|
.register_thread("user-hydrate", "gateway", thread_id, Arc::clone(&session))
|
||||||
|
.await;
|
||||||
|
|
||||||
|
// resolve_thread should find it (using the UUID as external_thread_id)
|
||||||
|
let (resolved_session, resolved_tid) = manager
|
||||||
|
.resolve_thread("user-hydrate", "gateway", Some(&thread_id.to_string()))
|
||||||
|
.await;
|
||||||
|
assert_eq!(resolved_tid, thread_id);
|
||||||
|
|
||||||
|
// Should be the same session object
|
||||||
|
let sess = resolved_session.lock().await;
|
||||||
|
assert!(sess.threads.contains_key(&thread_id));
|
||||||
|
}
|
||||||
|
|
||||||
|
#[tokio::test]
|
||||||
|
async fn test_resolve_thread_with_explicit_external_id() {
|
||||||
|
let manager = SessionManager::new();
|
||||||
|
|
||||||
|
// Two calls with the same explicit external thread ID should resolve
|
||||||
|
// to the same internal thread.
|
||||||
|
let (_, t1) = manager
|
||||||
|
.resolve_thread("user-1", "gateway", Some("ext-abc"))
|
||||||
|
.await;
|
||||||
|
let (_, t2) = manager
|
||||||
|
.resolve_thread("user-1", "gateway", Some("ext-abc"))
|
||||||
|
.await;
|
||||||
|
assert_eq!(t1, t2);
|
||||||
|
|
||||||
|
// A different external ID on the same channel/user gets a new thread.
|
||||||
|
let (_, t3) = manager
|
||||||
|
.resolve_thread("user-1", "gateway", Some("ext-xyz"))
|
||||||
|
.await;
|
||||||
|
assert_ne!(t1, t3);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[tokio::test]
|
||||||
|
async fn test_resolve_thread_none_vs_some_external_id() {
|
||||||
|
let manager = SessionManager::new();
|
||||||
|
|
||||||
|
// None external_thread_id is a distinct key from Some("ext-1").
|
||||||
|
let (_, t_none) = manager.resolve_thread("user-1", "cli", None).await;
|
||||||
|
let (_, t_some) = manager.resolve_thread("user-1", "cli", Some("ext-1")).await;
|
||||||
|
assert_ne!(t_none, t_some);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[tokio::test]
|
||||||
|
async fn test_resolve_thread_different_users_isolated() {
|
||||||
|
let manager = SessionManager::new();
|
||||||
|
|
||||||
|
let (_, t1) = manager
|
||||||
|
.resolve_thread("user-a", "gateway", Some("same-ext"))
|
||||||
|
.await;
|
||||||
|
let (_, t2) = manager
|
||||||
|
.resolve_thread("user-b", "gateway", Some("same-ext"))
|
||||||
|
.await;
|
||||||
|
|
||||||
|
// Same channel + same external ID but different users = different threads
|
||||||
|
assert_ne!(t1, t2);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[tokio::test]
|
||||||
|
async fn test_resolve_thread_different_channels_isolated() {
|
||||||
|
let manager = SessionManager::new();
|
||||||
|
|
||||||
|
let (_, t1) = manager
|
||||||
|
.resolve_thread("user-1", "gateway", Some("thread-x"))
|
||||||
|
.await;
|
||||||
|
let (_, t2) = manager
|
||||||
|
.resolve_thread("user-1", "telegram", Some("thread-x"))
|
||||||
|
.await;
|
||||||
|
|
||||||
|
// Same user + same external ID but different channels = different threads
|
||||||
|
assert_ne!(t1, t2);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[tokio::test]
|
||||||
|
async fn test_resolve_thread_stale_mapping_creates_new_thread() {
|
||||||
|
let manager = SessionManager::new();
|
||||||
|
|
||||||
|
// Create a thread normally
|
||||||
|
let (session, original_tid) = manager
|
||||||
|
.resolve_thread("user-1", "gateway", Some("ext-1"))
|
||||||
|
.await;
|
||||||
|
|
||||||
|
// Simulate the thread being removed from the session (e.g. pruned)
|
||||||
|
{
|
||||||
|
let mut sess = session.lock().await;
|
||||||
|
sess.threads.remove(&original_tid);
|
||||||
|
}
|
||||||
|
|
||||||
|
// Next resolve should detect the stale mapping and create a fresh thread
|
||||||
|
let (_, new_tid) = manager
|
||||||
|
.resolve_thread("user-1", "gateway", Some("ext-1"))
|
||||||
|
.await;
|
||||||
|
assert_ne!(original_tid, new_tid);
|
||||||
|
|
||||||
|
// The new thread should actually exist in the session
|
||||||
|
let sess = session.lock().await;
|
||||||
|
assert!(sess.threads.contains_key(&new_tid));
|
||||||
|
}
|
||||||
|
|
||||||
|
#[tokio::test]
|
||||||
|
async fn test_register_thread_preserves_uuid_on_resolve() {
|
||||||
|
use crate::agent::session::{Session, Thread};
|
||||||
|
|
||||||
|
let manager = SessionManager::new();
|
||||||
|
let known_uuid = Uuid::new_v4();
|
||||||
|
|
||||||
|
let session = Arc::new(Mutex::new(Session::new("user-web")));
|
||||||
|
let session_id = {
|
||||||
|
let sess = session.lock().await;
|
||||||
|
sess.id
|
||||||
|
};
|
||||||
|
|
||||||
|
// Simulate hydration: create thread with a known UUID
|
||||||
|
{
|
||||||
|
let mut sess = session.lock().await;
|
||||||
|
let thread = Thread::with_id(known_uuid, session_id);
|
||||||
|
sess.threads.insert(known_uuid, thread);
|
||||||
|
}
|
||||||
|
|
||||||
|
// Register it
|
||||||
|
manager
|
||||||
|
.register_thread("user-web", "gateway", known_uuid, Arc::clone(&session))
|
||||||
|
.await;
|
||||||
|
|
||||||
|
// resolve_thread with UUID as external_thread_id MUST return the same UUID,
|
||||||
|
// not mint a new one (this was the root cause of the "wrong conversation" bug)
|
||||||
|
let (_, resolved) = manager
|
||||||
|
.resolve_thread("user-web", "gateway", Some(&known_uuid.to_string()))
|
||||||
|
.await;
|
||||||
|
assert_eq!(resolved, known_uuid);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[tokio::test]
|
||||||
|
async fn test_register_thread_idempotent() {
|
||||||
|
use crate::agent::session::{Session, Thread};
|
||||||
|
|
||||||
|
let manager = SessionManager::new();
|
||||||
|
let tid = Uuid::new_v4();
|
||||||
|
|
||||||
|
let session = Arc::new(Mutex::new(Session::new("user-idem")));
|
||||||
|
{
|
||||||
|
let mut sess = session.lock().await;
|
||||||
|
let thread = Thread::with_id(tid, sess.id);
|
||||||
|
sess.threads.insert(tid, thread);
|
||||||
|
}
|
||||||
|
|
||||||
|
// Register twice
|
||||||
|
manager
|
||||||
|
.register_thread("user-idem", "gateway", tid, Arc::clone(&session))
|
||||||
|
.await;
|
||||||
|
manager
|
||||||
|
.register_thread("user-idem", "gateway", tid, Arc::clone(&session))
|
||||||
|
.await;
|
||||||
|
|
||||||
|
// Should still resolve to the same thread
|
||||||
|
let (_, resolved) = manager
|
||||||
|
.resolve_thread("user-idem", "gateway", Some(&tid.to_string()))
|
||||||
|
.await;
|
||||||
|
assert_eq!(resolved, tid);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[tokio::test]
|
||||||
|
async fn test_register_thread_creates_undo_manager() {
|
||||||
|
use crate::agent::session::{Session, Thread};
|
||||||
|
|
||||||
|
let manager = SessionManager::new();
|
||||||
|
let tid = Uuid::new_v4();
|
||||||
|
|
||||||
|
let session = Arc::new(Mutex::new(Session::new("user-undo")));
|
||||||
|
{
|
||||||
|
let mut sess = session.lock().await;
|
||||||
|
let thread = Thread::with_id(tid, sess.id);
|
||||||
|
sess.threads.insert(tid, thread);
|
||||||
|
}
|
||||||
|
|
||||||
|
manager
|
||||||
|
.register_thread("user-undo", "gateway", tid, Arc::clone(&session))
|
||||||
|
.await;
|
||||||
|
|
||||||
|
// Undo manager should exist for the registered thread
|
||||||
|
let undo = manager.get_undo_manager(tid).await;
|
||||||
|
let undo2 = manager.get_undo_manager(tid).await;
|
||||||
|
assert!(Arc::ptr_eq(&undo, &undo2));
|
||||||
|
}
|
||||||
|
|
||||||
|
#[tokio::test]
|
||||||
|
async fn test_register_thread_stores_session() {
|
||||||
|
use crate::agent::session::{Session, Thread};
|
||||||
|
|
||||||
|
let manager = SessionManager::new();
|
||||||
|
let tid = Uuid::new_v4();
|
||||||
|
|
||||||
|
let session = Arc::new(Mutex::new(Session::new("user-new")));
|
||||||
|
{
|
||||||
|
let mut sess = session.lock().await;
|
||||||
|
let thread = Thread::with_id(tid, sess.id);
|
||||||
|
sess.threads.insert(tid, thread);
|
||||||
|
}
|
||||||
|
|
||||||
|
// The user has no session yet in the manager
|
||||||
|
{
|
||||||
|
let sessions = manager.sessions.read().await;
|
||||||
|
assert!(!sessions.contains_key("user-new"));
|
||||||
|
}
|
||||||
|
|
||||||
|
manager
|
||||||
|
.register_thread("user-new", "gateway", tid, Arc::clone(&session))
|
||||||
|
.await;
|
||||||
|
|
||||||
|
// Now the session should be tracked
|
||||||
|
{
|
||||||
|
let sessions = manager.sessions.read().await;
|
||||||
|
assert!(sessions.contains_key("user-new"));
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
#[tokio::test]
|
||||||
|
async fn test_multiple_threads_per_user() {
|
||||||
|
let manager = SessionManager::new();
|
||||||
|
|
||||||
|
let (_, t1) = manager
|
||||||
|
.resolve_thread("user-1", "gateway", Some("thread-a"))
|
||||||
|
.await;
|
||||||
|
let (_, t2) = manager
|
||||||
|
.resolve_thread("user-1", "gateway", Some("thread-b"))
|
||||||
|
.await;
|
||||||
|
let (session, t3) = manager
|
||||||
|
.resolve_thread("user-1", "gateway", Some("thread-c"))
|
||||||
|
.await;
|
||||||
|
|
||||||
|
// All three should be distinct
|
||||||
|
assert_ne!(t1, t2);
|
||||||
|
assert_ne!(t2, t3);
|
||||||
|
assert_ne!(t1, t3);
|
||||||
|
|
||||||
|
// All three should exist in the same session
|
||||||
|
let sess = session.lock().await;
|
||||||
|
assert!(sess.threads.contains_key(&t1));
|
||||||
|
assert!(sess.threads.contains_key(&t2));
|
||||||
|
assert!(sess.threads.contains_key(&t3));
|
||||||
|
}
|
||||||
|
|
||||||
|
#[tokio::test]
|
||||||
|
async fn test_prune_cleans_thread_map_and_undo_managers() {
|
||||||
|
let manager = SessionManager::new();
|
||||||
|
|
||||||
|
let (stale_session, stale_tid) = manager.resolve_thread("user-stale", "cli", None).await;
|
||||||
|
|
||||||
|
// Backdate the session
|
||||||
|
{
|
||||||
|
let mut sess = stale_session.lock().await;
|
||||||
|
sess.last_active_at = chrono::Utc::now() - chrono::TimeDelta::seconds(86400 * 30);
|
||||||
|
}
|
||||||
|
|
||||||
|
// Verify thread_map and undo_managers have entries
|
||||||
|
{
|
||||||
|
let tm = manager.thread_map.read().await;
|
||||||
|
assert!(!tm.is_empty());
|
||||||
|
}
|
||||||
|
{
|
||||||
|
let um = manager.undo_managers.read().await;
|
||||||
|
assert!(um.contains_key(&stale_tid));
|
||||||
|
}
|
||||||
|
|
||||||
|
let pruned = manager
|
||||||
|
.prune_stale_sessions(std::time::Duration::from_secs(86400 * 7))
|
||||||
|
.await;
|
||||||
|
assert_eq!(pruned, 1);
|
||||||
|
|
||||||
|
// Thread map and undo managers should be cleaned up
|
||||||
|
{
|
||||||
|
let tm = manager.thread_map.read().await;
|
||||||
|
assert!(tm.is_empty());
|
||||||
|
}
|
||||||
|
{
|
||||||
|
let um = manager.undo_managers.read().await;
|
||||||
|
assert!(!um.contains_key(&stale_tid));
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
#[tokio::test]
|
||||||
|
async fn test_resolve_thread_active_thread_set() {
|
||||||
|
let manager = SessionManager::new();
|
||||||
|
|
||||||
|
let (session, thread_id) = manager
|
||||||
|
.resolve_thread("user-1", "gateway", Some("ext-1"))
|
||||||
|
.await;
|
||||||
|
|
||||||
|
// The resolved thread should be set as the active thread
|
||||||
|
let sess = session.lock().await;
|
||||||
|
assert_eq!(sess.active_thread, Some(thread_id));
|
||||||
|
}
|
||||||
|
|
||||||
|
#[tokio::test]
|
||||||
|
async fn test_register_then_resolve_different_channel_creates_new() {
|
||||||
|
use crate::agent::session::{Session, Thread};
|
||||||
|
|
||||||
|
let manager = SessionManager::new();
|
||||||
|
let tid = Uuid::new_v4();
|
||||||
|
|
||||||
|
let session = Arc::new(Mutex::new(Session::new("user-cross")));
|
||||||
|
{
|
||||||
|
let mut sess = session.lock().await;
|
||||||
|
let thread = Thread::with_id(tid, sess.id);
|
||||||
|
sess.threads.insert(tid, thread);
|
||||||
|
}
|
||||||
|
|
||||||
|
// Register on "gateway" channel
|
||||||
|
manager
|
||||||
|
.register_thread("user-cross", "gateway", tid, Arc::clone(&session))
|
||||||
|
.await;
|
||||||
|
|
||||||
|
// Resolve on a different channel with the same UUID string should NOT
|
||||||
|
// find the registered thread (channel is part of the key)
|
||||||
|
let (_, resolved) = manager
|
||||||
|
.resolve_thread("user-cross", "telegram", Some(&tid.to_string()))
|
||||||
|
.await;
|
||||||
|
assert_ne!(resolved, tid);
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
+141
-11
@@ -43,6 +43,49 @@ impl SubmissionParser {
|
|||||||
if lower == "/thread new" || lower == "/new" {
|
if lower == "/thread new" || lower == "/new" {
|
||||||
return Submission::NewThread;
|
return Submission::NewThread;
|
||||||
}
|
}
|
||||||
|
// System commands (bypass thread-state checks)
|
||||||
|
if lower == "/help" || lower == "/?" {
|
||||||
|
return Submission::SystemCommand {
|
||||||
|
command: "help".to_string(),
|
||||||
|
args: vec![],
|
||||||
|
};
|
||||||
|
}
|
||||||
|
if lower == "/version" {
|
||||||
|
return Submission::SystemCommand {
|
||||||
|
command: "version".to_string(),
|
||||||
|
args: vec![],
|
||||||
|
};
|
||||||
|
}
|
||||||
|
if lower == "/tools" {
|
||||||
|
return Submission::SystemCommand {
|
||||||
|
command: "tools".to_string(),
|
||||||
|
args: vec![],
|
||||||
|
};
|
||||||
|
}
|
||||||
|
if lower == "/ping" {
|
||||||
|
return Submission::SystemCommand {
|
||||||
|
command: "ping".to_string(),
|
||||||
|
args: vec![],
|
||||||
|
};
|
||||||
|
}
|
||||||
|
if lower == "/debug" {
|
||||||
|
return Submission::SystemCommand {
|
||||||
|
command: "debug".to_string(),
|
||||||
|
args: vec![],
|
||||||
|
};
|
||||||
|
}
|
||||||
|
if lower.starts_with("/model") {
|
||||||
|
let args: Vec<String> = trimmed
|
||||||
|
.split_whitespace()
|
||||||
|
.skip(1)
|
||||||
|
.map(|s| s.to_string())
|
||||||
|
.collect();
|
||||||
|
return Submission::SystemCommand {
|
||||||
|
command: "model".to_string(),
|
||||||
|
args,
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
if lower == "/quit" || lower == "/exit" || lower == "/shutdown" {
|
if lower == "/quit" || lower == "/exit" || lower == "/shutdown" {
|
||||||
return Submission::Quit;
|
return Submission::Quit;
|
||||||
}
|
}
|
||||||
@@ -50,28 +93,27 @@ impl SubmissionParser {
|
|||||||
// /thread <uuid> - switch thread
|
// /thread <uuid> - switch thread
|
||||||
if let Some(rest) = lower.strip_prefix("/thread ") {
|
if let Some(rest) = lower.strip_prefix("/thread ") {
|
||||||
let rest = rest.trim();
|
let rest = rest.trim();
|
||||||
if rest != "new" {
|
if rest != "new"
|
||||||
if let Ok(id) = Uuid::parse_str(rest) {
|
&& let Ok(id) = Uuid::parse_str(rest)
|
||||||
|
{
|
||||||
return Submission::SwitchThread { thread_id: id };
|
return Submission::SwitchThread { thread_id: id };
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
|
||||||
|
|
||||||
// /resume <uuid> - resume from checkpoint
|
// /resume <uuid> - resume from checkpoint
|
||||||
if let Some(rest) = lower.strip_prefix("/resume ") {
|
if let Some(rest) = lower.strip_prefix("/resume ")
|
||||||
if let Ok(id) = Uuid::parse_str(rest.trim()) {
|
&& let Ok(id) = Uuid::parse_str(rest.trim())
|
||||||
|
{
|
||||||
return Submission::Resume { checkpoint_id: id };
|
return Submission::Resume { checkpoint_id: id };
|
||||||
}
|
}
|
||||||
}
|
|
||||||
|
|
||||||
// Try structured JSON approval (from web gateway's /api/chat/approval endpoint)
|
// Try structured JSON approval (from web gateway's /api/chat/approval endpoint)
|
||||||
if trimmed.starts_with('{') {
|
if trimmed.starts_with('{')
|
||||||
if let Ok(submission) = serde_json::from_str::<Submission>(trimmed) {
|
&& let Ok(submission) = serde_json::from_str::<Submission>(trimmed)
|
||||||
if matches!(submission, Submission::ExecApproval { .. }) {
|
&& matches!(submission, Submission::ExecApproval { .. })
|
||||||
|
{
|
||||||
return submission;
|
return submission;
|
||||||
}
|
}
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// Approval responses (simple yes/no/always for pending approvals)
|
// Approval responses (simple yes/no/always for pending approvals)
|
||||||
// These are short enough to check explicitly
|
// These are short enough to check explicitly
|
||||||
@@ -172,6 +214,15 @@ pub enum Submission {
|
|||||||
|
|
||||||
/// Quit the agent. Bypasses thread-state checks.
|
/// Quit the agent. Bypasses thread-state checks.
|
||||||
Quit,
|
Quit,
|
||||||
|
|
||||||
|
/// System command (help, model, version, tools, ping, debug).
|
||||||
|
/// Bypasses thread-state checks and safety validation.
|
||||||
|
SystemCommand {
|
||||||
|
/// The command name (e.g. "help", "model", "version").
|
||||||
|
command: String,
|
||||||
|
/// Arguments to the command.
|
||||||
|
args: Vec<String>,
|
||||||
|
},
|
||||||
}
|
}
|
||||||
|
|
||||||
impl Submission {
|
impl Submission {
|
||||||
@@ -238,6 +289,7 @@ impl Submission {
|
|||||||
| Self::Heartbeat
|
| Self::Heartbeat
|
||||||
| Self::Summarize
|
| Self::Summarize
|
||||||
| Self::Suggest
|
| Self::Suggest
|
||||||
|
| Self::SystemCommand { .. }
|
||||||
)
|
)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -504,6 +556,84 @@ mod tests {
|
|||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_parser_system_command_help() {
|
||||||
|
let submission = SubmissionParser::parse("/help");
|
||||||
|
assert!(
|
||||||
|
matches!(submission, Submission::SystemCommand { command, args } if command == "help" && args.is_empty())
|
||||||
|
);
|
||||||
|
|
||||||
|
let submission = SubmissionParser::parse("/?");
|
||||||
|
assert!(
|
||||||
|
matches!(submission, Submission::SystemCommand { command, .. } if command == "help")
|
||||||
|
);
|
||||||
|
|
||||||
|
let submission = SubmissionParser::parse("/HELP");
|
||||||
|
assert!(
|
||||||
|
matches!(submission, Submission::SystemCommand { command, .. } if command == "help")
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_parser_system_command_model() {
|
||||||
|
// No args: show current model
|
||||||
|
let submission = SubmissionParser::parse("/model");
|
||||||
|
assert!(
|
||||||
|
matches!(submission, Submission::SystemCommand { command, args } if command == "model" && args.is_empty())
|
||||||
|
);
|
||||||
|
|
||||||
|
// With args: switch model
|
||||||
|
let submission = SubmissionParser::parse("/model gpt-4o");
|
||||||
|
assert!(
|
||||||
|
matches!(submission, Submission::SystemCommand { command, args } if command == "model" && args == vec!["gpt-4o"])
|
||||||
|
);
|
||||||
|
|
||||||
|
// Case insensitive command, preserves arg case
|
||||||
|
let submission = SubmissionParser::parse("/MODEL Claude-3.5");
|
||||||
|
assert!(
|
||||||
|
matches!(submission, Submission::SystemCommand { command, args } if command == "model" && args == vec!["Claude-3.5"])
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_parser_system_command_version() {
|
||||||
|
let submission = SubmissionParser::parse("/version");
|
||||||
|
assert!(
|
||||||
|
matches!(submission, Submission::SystemCommand { command, args } if command == "version" && args.is_empty())
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_parser_system_command_tools() {
|
||||||
|
let submission = SubmissionParser::parse("/tools");
|
||||||
|
assert!(
|
||||||
|
matches!(submission, Submission::SystemCommand { command, args } if command == "tools" && args.is_empty())
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_parser_system_command_ping() {
|
||||||
|
let submission = SubmissionParser::parse("/ping");
|
||||||
|
assert!(
|
||||||
|
matches!(submission, Submission::SystemCommand { command, args } if command == "ping" && args.is_empty())
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_parser_system_command_debug() {
|
||||||
|
let submission = SubmissionParser::parse("/debug");
|
||||||
|
assert!(
|
||||||
|
matches!(submission, Submission::SystemCommand { command, args } if command == "debug" && args.is_empty())
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_parser_system_command_is_control() {
|
||||||
|
let submission = SubmissionParser::parse("/help");
|
||||||
|
assert!(submission.is_control());
|
||||||
|
assert!(!submission.starts_turn());
|
||||||
|
}
|
||||||
|
|
||||||
#[test]
|
#[test]
|
||||||
fn test_parser_quit() {
|
fn test_parser_quit() {
|
||||||
assert!(matches!(SubmissionParser::parse("/quit"), Submission::Quit));
|
assert!(matches!(SubmissionParser::parse("/quit"), Submission::Quit));
|
||||||
|
|||||||
+160
-33
@@ -10,8 +10,8 @@ use uuid::Uuid;
|
|||||||
use crate::agent::scheduler::WorkerMessage;
|
use crate::agent::scheduler::WorkerMessage;
|
||||||
use crate::agent::task::TaskOutput;
|
use crate::agent::task::TaskOutput;
|
||||||
use crate::context::{ContextManager, JobState};
|
use crate::context::{ContextManager, JobState};
|
||||||
|
use crate::db::Database;
|
||||||
use crate::error::Error;
|
use crate::error::Error;
|
||||||
use crate::history::Store;
|
|
||||||
use crate::llm::{
|
use crate::llm::{
|
||||||
ActionPlan, ChatMessage, LlmProvider, Reasoning, ReasoningContext, RespondResult, ToolSelection,
|
ActionPlan, ChatMessage, LlmProvider, Reasoning, ReasoningContext, RespondResult, ToolSelection,
|
||||||
};
|
};
|
||||||
@@ -28,7 +28,7 @@ pub struct WorkerDeps {
|
|||||||
pub llm: Arc<dyn LlmProvider>,
|
pub llm: Arc<dyn LlmProvider>,
|
||||||
pub safety: Arc<SafetyLayer>,
|
pub safety: Arc<SafetyLayer>,
|
||||||
pub tools: Arc<ToolRegistry>,
|
pub tools: Arc<ToolRegistry>,
|
||||||
pub store: Option<Arc<Store>>,
|
pub store: Option<Arc<dyn Database>>,
|
||||||
pub timeout: Duration,
|
pub timeout: Duration,
|
||||||
pub use_planning: bool,
|
pub use_planning: bool,
|
||||||
}
|
}
|
||||||
@@ -67,7 +67,7 @@ impl Worker {
|
|||||||
&self.deps.tools
|
&self.deps.tools
|
||||||
}
|
}
|
||||||
|
|
||||||
fn store(&self) -> Option<&Arc<Store>> {
|
fn store(&self) -> Option<&Arc<dyn Database>> {
|
||||||
self.deps.store.as_ref()
|
self.deps.store.as_ref()
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -227,12 +227,12 @@ Report when the job is complete or if you encounter issues you cannot resolve."#
|
|||||||
}
|
}
|
||||||
|
|
||||||
// Check for cancellation
|
// Check for cancellation
|
||||||
if let Ok(ctx) = self.context_manager().get_context(self.job_id).await {
|
if let Ok(ctx) = self.context_manager().get_context(self.job_id).await
|
||||||
if ctx.state == JobState::Cancelled {
|
&& ctx.state == JobState::Cancelled
|
||||||
|
{
|
||||||
tracing::info!("Worker for job {} detected cancellation", self.job_id);
|
tracing::info!("Worker for job {} detected cancellation", self.job_id);
|
||||||
return Ok(());
|
return Ok(());
|
||||||
}
|
}
|
||||||
}
|
|
||||||
|
|
||||||
iteration += 1;
|
iteration += 1;
|
||||||
if iteration > max_iterations {
|
if iteration > max_iterations {
|
||||||
@@ -248,16 +248,15 @@ Report when the job is complete or if you encounter issues you cannot resolve."#
|
|||||||
|
|
||||||
if selections.is_empty() {
|
if selections.is_empty() {
|
||||||
// No tools from select_tools, ask LLM directly (may still return tool calls)
|
// No tools from select_tools, ask LLM directly (may still return tool calls)
|
||||||
let respond_result = reasoning.respond_with_tools(reason_ctx).await?;
|
let respond_output = reasoning.respond_with_tools(reason_ctx).await?;
|
||||||
|
|
||||||
match respond_result {
|
match respond_output.result {
|
||||||
RespondResult::Text(response) => {
|
RespondResult::Text(response) => {
|
||||||
// Check for completion keywords
|
// Check for explicit completion phrases. Use word-boundary
|
||||||
let response_lower = response.to_lowercase();
|
// aware checks to avoid false positives like "incomplete",
|
||||||
if response_lower.contains("complete")
|
// "not done", or "unfinished". Only the LLM's own response
|
||||||
|| response_lower.contains("finished")
|
// (not tool output) can trigger this.
|
||||||
|| response_lower.contains("done")
|
if crate::util::llm_signals_completion(&response) {
|
||||||
{
|
|
||||||
self.mark_completed().await?;
|
self.mark_completed().await?;
|
||||||
return Ok(());
|
return Ok(());
|
||||||
}
|
}
|
||||||
@@ -272,7 +271,10 @@ Report when the job is complete or if you encounter issues you cannot resolve."#
|
|||||||
));
|
));
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
RespondResult::ToolCalls(tool_calls) => {
|
RespondResult::ToolCalls {
|
||||||
|
tool_calls,
|
||||||
|
content,
|
||||||
|
} => {
|
||||||
// Model returned tool calls - execute them
|
// Model returned tool calls - execute them
|
||||||
tracing::debug!(
|
tracing::debug!(
|
||||||
"Job {} respond_with_tools returned {} tool calls",
|
"Job {} respond_with_tools returned {} tool calls",
|
||||||
@@ -280,6 +282,14 @@ Report when the job is complete or if you encounter issues you cannot resolve."#
|
|||||||
tool_calls.len()
|
tool_calls.len()
|
||||||
);
|
);
|
||||||
|
|
||||||
|
// Add assistant message with tool_calls (OpenAI protocol)
|
||||||
|
reason_ctx
|
||||||
|
.messages
|
||||||
|
.push(ChatMessage::assistant_with_tool_calls(
|
||||||
|
content,
|
||||||
|
tool_calls.clone(),
|
||||||
|
));
|
||||||
|
|
||||||
for tc in tool_calls {
|
for tc in tool_calls {
|
||||||
let result = self.execute_tool(&tc.name, &tc.arguments).await;
|
let result = self.execute_tool(&tc.name, &tc.arguments).await;
|
||||||
|
|
||||||
@@ -289,6 +299,7 @@ Report when the job is complete or if you encounter issues you cannot resolve."#
|
|||||||
parameters: tc.arguments.clone(),
|
parameters: tc.arguments.clone(),
|
||||||
reasoning: String::new(),
|
reasoning: String::new(),
|
||||||
alternatives: vec![],
|
alternatives: vec![],
|
||||||
|
tool_call_id: tc.id.clone(),
|
||||||
};
|
};
|
||||||
|
|
||||||
self.process_tool_result(reason_ctx, &selection, result)
|
self.process_tool_result(reason_ctx, &selection, result)
|
||||||
@@ -371,7 +382,7 @@ Report when the job is complete or if you encounter issues you cannot resolve."#
|
|||||||
tools: Arc<ToolRegistry>,
|
tools: Arc<ToolRegistry>,
|
||||||
context_manager: Arc<ContextManager>,
|
context_manager: Arc<ContextManager>,
|
||||||
safety: Arc<SafetyLayer>,
|
safety: Arc<SafetyLayer>,
|
||||||
store: Option<Arc<Store>>,
|
store: Option<Arc<dyn Database>>,
|
||||||
job_id: Uuid,
|
job_id: Uuid,
|
||||||
tool_name: &str,
|
tool_name: &str,
|
||||||
params: &serde_json::Value,
|
params: &serde_json::Value,
|
||||||
@@ -417,14 +428,51 @@ Report when the job is complete or if you encounter issues you cannot resolve."#
|
|||||||
.into());
|
.into());
|
||||||
}
|
}
|
||||||
|
|
||||||
// Execute with timeout and timing
|
tracing::debug!(
|
||||||
|
tool = %tool_name,
|
||||||
|
params = %params,
|
||||||
|
job = %job_id,
|
||||||
|
"Tool call started"
|
||||||
|
);
|
||||||
|
|
||||||
|
// Execute with per-tool timeout and timing
|
||||||
|
let tool_timeout = tool.execution_timeout();
|
||||||
let start = std::time::Instant::now();
|
let start = std::time::Instant::now();
|
||||||
let result = tokio::time::timeout(Duration::from_secs(60), async {
|
let result = tokio::time::timeout(tool_timeout, async {
|
||||||
tool.execute(params.clone(), &job_ctx).await
|
tool.execute(params.clone(), &job_ctx).await
|
||||||
})
|
})
|
||||||
.await;
|
.await;
|
||||||
let elapsed = start.elapsed();
|
let elapsed = start.elapsed();
|
||||||
|
|
||||||
|
match &result {
|
||||||
|
Ok(Ok(output)) => {
|
||||||
|
let result_str = serde_json::to_string(&output.result)
|
||||||
|
.unwrap_or_else(|_| "<serialize error>".to_string());
|
||||||
|
tracing::debug!(
|
||||||
|
tool = %tool_name,
|
||||||
|
elapsed_ms = elapsed.as_millis() as u64,
|
||||||
|
result = %result_str,
|
||||||
|
"Tool call succeeded"
|
||||||
|
);
|
||||||
|
}
|
||||||
|
Ok(Err(e)) => {
|
||||||
|
tracing::debug!(
|
||||||
|
tool = %tool_name,
|
||||||
|
elapsed_ms = elapsed.as_millis() as u64,
|
||||||
|
error = %e,
|
||||||
|
"Tool call failed"
|
||||||
|
);
|
||||||
|
}
|
||||||
|
Err(_) => {
|
||||||
|
tracing::debug!(
|
||||||
|
tool = %tool_name,
|
||||||
|
elapsed_ms = elapsed.as_millis() as u64,
|
||||||
|
timeout_secs = tool_timeout.as_secs(),
|
||||||
|
"Tool call timed out"
|
||||||
|
);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
// Record action in memory and get the ActionRecord for persistence
|
// Record action in memory and get the ActionRecord for persistence
|
||||||
let action = match &result {
|
let action = match &result {
|
||||||
Ok(Ok(output)) => {
|
Ok(Ok(output)) => {
|
||||||
@@ -479,7 +527,7 @@ Report when the job is complete or if you encounter issues you cannot resolve."#
|
|||||||
let output = result
|
let output = result
|
||||||
.map_err(|_| crate::error::ToolError::Timeout {
|
.map_err(|_| crate::error::ToolError::Timeout {
|
||||||
name: tool_name.to_string(),
|
name: tool_name.to_string(),
|
||||||
timeout: Duration::from_secs(60),
|
timeout: tool_timeout,
|
||||||
})?
|
})?
|
||||||
.map_err(|e| crate::error::ToolError::ExecutionFailed {
|
.map_err(|e| crate::error::ToolError::ExecutionFailed {
|
||||||
name: tool_name.to_string(),
|
name: tool_name.to_string(),
|
||||||
@@ -518,17 +566,14 @@ Report when the job is complete or if you encounter issues you cannot resolve."#
|
|||||||
);
|
);
|
||||||
|
|
||||||
reason_ctx.messages.push(ChatMessage::tool_result(
|
reason_ctx.messages.push(ChatMessage::tool_result(
|
||||||
"tool_call_id",
|
&selection.tool_call_id,
|
||||||
&selection.tool_name,
|
&selection.tool_name,
|
||||||
wrapped,
|
wrapped,
|
||||||
));
|
));
|
||||||
|
|
||||||
// Check if job is complete
|
// Tool output never drives job completion. A malicious tool could
|
||||||
if output.contains("TASK_COMPLETE") || output.contains("JOB_DONE") {
|
// emit "TASK_COMPLETE" to force premature completion. Only the LLM's
|
||||||
self.mark_completed().await?;
|
// own structured response (in execution_loop) can mark a job done.
|
||||||
return Ok(true);
|
|
||||||
}
|
|
||||||
|
|
||||||
Ok(false)
|
Ok(false)
|
||||||
}
|
}
|
||||||
Err(e) => {
|
Err(e) => {
|
||||||
@@ -553,7 +598,7 @@ Report when the job is complete or if you encounter issues you cannot resolve."#
|
|||||||
}
|
}
|
||||||
|
|
||||||
reason_ctx.messages.push(ChatMessage::tool_result(
|
reason_ctx.messages.push(ChatMessage::tool_result(
|
||||||
"tool_call_id",
|
&selection.tool_call_id,
|
||||||
&selection.tool_name,
|
&selection.tool_name,
|
||||||
format!("Error: {}", e),
|
format!("Error: {}", e),
|
||||||
));
|
));
|
||||||
@@ -603,12 +648,15 @@ Report when the job is complete or if you encounter issues you cannot resolve."#
|
|||||||
.execute_tool(&action.tool_name, &action.parameters)
|
.execute_tool(&action.tool_name, &action.parameters)
|
||||||
.await;
|
.await;
|
||||||
|
|
||||||
// Create a synthetic ToolSelection for process_tool_result
|
// Create a synthetic ToolSelection for process_tool_result.
|
||||||
|
// Plan actions don't originate from an LLM tool_call response so
|
||||||
|
// there is no real tool_call_id; generate a unique one.
|
||||||
let selection = ToolSelection {
|
let selection = ToolSelection {
|
||||||
tool_name: action.tool_name.clone(),
|
tool_name: action.tool_name.clone(),
|
||||||
parameters: action.parameters.clone(),
|
parameters: action.parameters.clone(),
|
||||||
reasoning: action.reasoning.clone(),
|
reasoning: action.reasoning.clone(),
|
||||||
alternatives: vec![],
|
alternatives: vec![],
|
||||||
|
tool_call_id: format!("plan_{}_{}", self.job_id, i),
|
||||||
};
|
};
|
||||||
|
|
||||||
// Process the result
|
// Process the result
|
||||||
@@ -632,11 +680,7 @@ Report when the job is complete or if you encounter issues you cannot resolve."#
|
|||||||
let response = reasoning.respond(reason_ctx).await?;
|
let response = reasoning.respond(reason_ctx).await?;
|
||||||
reason_ctx.messages.push(ChatMessage::assistant(&response));
|
reason_ctx.messages.push(ChatMessage::assistant(&response));
|
||||||
|
|
||||||
let response_lower = response.to_lowercase();
|
if crate::util::llm_signals_completion(&response) {
|
||||||
if response_lower.contains("complete")
|
|
||||||
|| response_lower.contains("finished")
|
|
||||||
|| response_lower.contains("done")
|
|
||||||
{
|
|
||||||
self.mark_completed().await?;
|
self.mark_completed().await?;
|
||||||
} else {
|
} else {
|
||||||
// Job not complete, could re-plan or fall back to direct selection
|
// Job not complete, could re-plan or fall back to direct selection
|
||||||
@@ -731,3 +775,86 @@ impl From<TaskOutput> for Result<String, Error> {
|
|||||||
})
|
})
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
#[cfg(test)]
|
||||||
|
mod tests {
|
||||||
|
use crate::llm::ToolSelection;
|
||||||
|
use crate::util::llm_signals_completion;
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_tool_selection_preserves_call_id() {
|
||||||
|
let selection = ToolSelection {
|
||||||
|
tool_name: "memory_search".to_string(),
|
||||||
|
parameters: serde_json::json!({"query": "test"}),
|
||||||
|
reasoning: "Need to search memory".to_string(),
|
||||||
|
alternatives: vec![],
|
||||||
|
tool_call_id: "call_abc123".to_string(),
|
||||||
|
};
|
||||||
|
|
||||||
|
assert_eq!(selection.tool_call_id, "call_abc123");
|
||||||
|
assert_ne!(
|
||||||
|
selection.tool_call_id, "tool_call_id",
|
||||||
|
"tool_call_id must not be the hardcoded placeholder string"
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_completion_positive_signals() {
|
||||||
|
assert!(llm_signals_completion("The job is complete."));
|
||||||
|
assert!(llm_signals_completion(
|
||||||
|
"I have completed the task successfully."
|
||||||
|
));
|
||||||
|
assert!(llm_signals_completion("The task is done."));
|
||||||
|
assert!(llm_signals_completion("The task is finished."));
|
||||||
|
assert!(llm_signals_completion(
|
||||||
|
"All steps are complete and verified."
|
||||||
|
));
|
||||||
|
assert!(llm_signals_completion(
|
||||||
|
"I've done all the work. The work is done."
|
||||||
|
));
|
||||||
|
assert!(llm_signals_completion(
|
||||||
|
"Successfully completed the migration."
|
||||||
|
));
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_completion_negative_signals_block_false_positives() {
|
||||||
|
// These contain completion keywords but also negation, should NOT trigger.
|
||||||
|
assert!(!llm_signals_completion("The task is not complete yet."));
|
||||||
|
assert!(!llm_signals_completion("This is not done."));
|
||||||
|
assert!(!llm_signals_completion("The work is incomplete."));
|
||||||
|
assert!(!llm_signals_completion(
|
||||||
|
"The migration is not yet finished."
|
||||||
|
));
|
||||||
|
assert!(!llm_signals_completion("The job isn't done yet."));
|
||||||
|
assert!(!llm_signals_completion("This remains unfinished."));
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_completion_does_not_match_bare_substrings() {
|
||||||
|
// Bare words embedded in other text should NOT trigger completion.
|
||||||
|
assert!(!llm_signals_completion(
|
||||||
|
"I need to complete more work first."
|
||||||
|
));
|
||||||
|
assert!(!llm_signals_completion(
|
||||||
|
"Let me finish the remaining steps."
|
||||||
|
));
|
||||||
|
assert!(!llm_signals_completion(
|
||||||
|
"I'm done analyzing, now let me fix it."
|
||||||
|
));
|
||||||
|
assert!(!llm_signals_completion(
|
||||||
|
"I completed step 1 but step 2 remains."
|
||||||
|
));
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_completion_tool_output_injection() {
|
||||||
|
// A malicious tool output echoed by the LLM should not trigger
|
||||||
|
// completion unless it forms a genuine completion phrase.
|
||||||
|
assert!(!llm_signals_completion("TASK_COMPLETE"));
|
||||||
|
assert!(!llm_signals_completion("JOB_DONE"));
|
||||||
|
assert!(!llm_signals_completion(
|
||||||
|
"The tool returned: TASK_COMPLETE signal"
|
||||||
|
));
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|||||||
@@ -0,0 +1,464 @@
|
|||||||
|
//! Bootstrap helpers for IronClaw.
|
||||||
|
//!
|
||||||
|
//! The only setting that truly needs disk persistence before the database is
|
||||||
|
//! available is `DATABASE_URL` (chicken-and-egg: can't connect to DB without
|
||||||
|
//! it). Everything else is auto-detected or read from env vars.
|
||||||
|
//!
|
||||||
|
//! File: `~/.ironclaw/.env` (standard dotenvy format)
|
||||||
|
|
||||||
|
use std::path::PathBuf;
|
||||||
|
|
||||||
|
/// Path to the IronClaw-specific `.env` file: `~/.ironclaw/.env`.
|
||||||
|
pub fn ironclaw_env_path() -> PathBuf {
|
||||||
|
dirs::home_dir()
|
||||||
|
.unwrap_or_else(|| PathBuf::from("."))
|
||||||
|
.join(".ironclaw")
|
||||||
|
.join(".env")
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Load env vars from `~/.ironclaw/.env` (in addition to the standard `.env`).
|
||||||
|
///
|
||||||
|
/// Call this **after** `dotenvy::dotenv()` so that the standard `./.env`
|
||||||
|
/// takes priority over `~/.ironclaw/.env`. dotenvy never overwrites
|
||||||
|
/// existing env vars, so the effective priority is:
|
||||||
|
///
|
||||||
|
/// explicit env vars > `./.env` > `~/.ironclaw/.env`
|
||||||
|
///
|
||||||
|
/// If `~/.ironclaw/.env` doesn't exist but the legacy `bootstrap.json` does,
|
||||||
|
/// extracts `DATABASE_URL` from it and writes the `.env` file (one-time
|
||||||
|
/// upgrade from the old config format).
|
||||||
|
pub fn load_ironclaw_env() {
|
||||||
|
let path = ironclaw_env_path();
|
||||||
|
|
||||||
|
if !path.exists() {
|
||||||
|
// One-time upgrade: extract DATABASE_URL from legacy bootstrap.json
|
||||||
|
migrate_bootstrap_json_to_env(&path);
|
||||||
|
}
|
||||||
|
|
||||||
|
if path.exists() {
|
||||||
|
let _ = dotenvy::from_path(&path);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// If `bootstrap.json` exists, pull `database_url` out of it and write `.env`.
|
||||||
|
fn migrate_bootstrap_json_to_env(env_path: &std::path::Path) {
|
||||||
|
let ironclaw_dir = env_path
|
||||||
|
.parent()
|
||||||
|
.unwrap_or_else(|| std::path::Path::new("."));
|
||||||
|
let bootstrap_path = ironclaw_dir.join("bootstrap.json");
|
||||||
|
|
||||||
|
if !bootstrap_path.exists() {
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
let content = match std::fs::read_to_string(&bootstrap_path) {
|
||||||
|
Ok(c) => c,
|
||||||
|
Err(_) => return,
|
||||||
|
};
|
||||||
|
|
||||||
|
// Minimal parse: just grab database_url from the JSON
|
||||||
|
let parsed: serde_json::Value = match serde_json::from_str(&content) {
|
||||||
|
Ok(v) => v,
|
||||||
|
Err(_) => return,
|
||||||
|
};
|
||||||
|
|
||||||
|
if let Some(url) = parsed.get("database_url").and_then(|v| v.as_str()) {
|
||||||
|
if let Some(parent) = env_path.parent()
|
||||||
|
&& let Err(e) = std::fs::create_dir_all(parent)
|
||||||
|
{
|
||||||
|
eprintln!("Warning: failed to create {}: {}", parent.display(), e);
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
if let Err(e) = std::fs::write(env_path, format!("DATABASE_URL=\"{}\"\n", url)) {
|
||||||
|
eprintln!("Warning: failed to migrate bootstrap.json to .env: {}", e);
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
rename_to_migrated(&bootstrap_path);
|
||||||
|
eprintln!(
|
||||||
|
"Migrated DATABASE_URL from bootstrap.json to {}",
|
||||||
|
env_path.display()
|
||||||
|
);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Write database bootstrap vars to `~/.ironclaw/.env`.
|
||||||
|
///
|
||||||
|
/// These settings form the chicken-and-egg layer: they must be available
|
||||||
|
/// from the filesystem (env vars) BEFORE any database connection, because
|
||||||
|
/// they determine which database to connect to. Everything else is stored
|
||||||
|
/// in the database itself.
|
||||||
|
///
|
||||||
|
/// Creates the parent directory if it doesn't exist.
|
||||||
|
/// Values are double-quoted so that `#` (common in URL-encoded passwords)
|
||||||
|
/// and other shell-special characters are preserved by dotenvy.
|
||||||
|
pub fn save_bootstrap_env(vars: &[(&str, &str)]) -> std::io::Result<()> {
|
||||||
|
let path = ironclaw_env_path();
|
||||||
|
if let Some(parent) = path.parent() {
|
||||||
|
std::fs::create_dir_all(parent)?;
|
||||||
|
}
|
||||||
|
let mut content = String::new();
|
||||||
|
for (key, value) in vars {
|
||||||
|
content.push_str(&format!("{}=\"{}\"\n", key, value));
|
||||||
|
}
|
||||||
|
std::fs::write(&path, content)
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Write `DATABASE_URL` to `~/.ironclaw/.env`.
|
||||||
|
///
|
||||||
|
/// Convenience wrapper around `save_bootstrap_env` for single-value migration
|
||||||
|
/// paths. Prefer `save_bootstrap_env` for new code.
|
||||||
|
pub fn save_database_url(url: &str) -> std::io::Result<()> {
|
||||||
|
save_bootstrap_env(&[("DATABASE_URL", url)])
|
||||||
|
}
|
||||||
|
|
||||||
|
/// One-time migration of legacy `~/.ironclaw/settings.json` into the database.
|
||||||
|
///
|
||||||
|
/// Only runs when a `settings.json` exists on disk AND the DB has no settings
|
||||||
|
/// yet. After the wizard writes directly to the DB, this path is only hit by
|
||||||
|
/// users upgrading from the old disk-only configuration.
|
||||||
|
///
|
||||||
|
/// After syncing, renames `settings.json` to `.migrated` so it won't trigger again.
|
||||||
|
pub async fn migrate_disk_to_db(
|
||||||
|
store: &dyn crate::db::Database,
|
||||||
|
user_id: &str,
|
||||||
|
) -> Result<(), MigrationError> {
|
||||||
|
let ironclaw_dir = dirs::home_dir()
|
||||||
|
.unwrap_or_else(|| PathBuf::from("."))
|
||||||
|
.join(".ironclaw");
|
||||||
|
let legacy_settings_path = ironclaw_dir.join("settings.json");
|
||||||
|
|
||||||
|
if !legacy_settings_path.exists() {
|
||||||
|
tracing::debug!("No legacy settings.json found, skipping disk-to-DB migration");
|
||||||
|
return Ok(());
|
||||||
|
}
|
||||||
|
|
||||||
|
// If DB already has settings, this is not a first boot, the wizard already
|
||||||
|
// wrote directly to the DB. Just clean up the stale file.
|
||||||
|
let has_settings = store.has_settings(user_id).await.map_err(|e| {
|
||||||
|
MigrationError::Database(format!("Failed to check existing settings: {}", e))
|
||||||
|
})?;
|
||||||
|
if has_settings {
|
||||||
|
tracing::info!("DB already has settings, renaming stale settings.json");
|
||||||
|
rename_to_migrated(&legacy_settings_path);
|
||||||
|
return Ok(());
|
||||||
|
}
|
||||||
|
|
||||||
|
tracing::info!("Migrating disk settings to database...");
|
||||||
|
|
||||||
|
// 1. Load and migrate settings.json
|
||||||
|
let settings = crate::settings::Settings::load_from(&legacy_settings_path);
|
||||||
|
let db_map = settings.to_db_map();
|
||||||
|
if !db_map.is_empty() {
|
||||||
|
store
|
||||||
|
.set_all_settings(user_id, &db_map)
|
||||||
|
.await
|
||||||
|
.map_err(|e| {
|
||||||
|
MigrationError::Database(format!("Failed to write settings to DB: {}", e))
|
||||||
|
})?;
|
||||||
|
tracing::info!("Migrated {} settings to database", db_map.len());
|
||||||
|
}
|
||||||
|
|
||||||
|
// 2. Write DATABASE_URL to ~/.ironclaw/.env
|
||||||
|
if let Some(ref url) = settings.database_url {
|
||||||
|
save_database_url(url)
|
||||||
|
.map_err(|e| MigrationError::Io(format!("Failed to write .env: {}", e)))?;
|
||||||
|
tracing::info!("Wrote DATABASE_URL to {}", ironclaw_env_path().display());
|
||||||
|
}
|
||||||
|
|
||||||
|
// 3. Migrate mcp-servers.json if it exists
|
||||||
|
let mcp_path = ironclaw_dir.join("mcp-servers.json");
|
||||||
|
if mcp_path.exists() {
|
||||||
|
match std::fs::read_to_string(&mcp_path) {
|
||||||
|
Ok(content) => match serde_json::from_str::<serde_json::Value>(&content) {
|
||||||
|
Ok(value) => {
|
||||||
|
store
|
||||||
|
.set_setting(user_id, "mcp_servers", &value)
|
||||||
|
.await
|
||||||
|
.map_err(|e| {
|
||||||
|
MigrationError::Database(format!(
|
||||||
|
"Failed to write MCP servers to DB: {}",
|
||||||
|
e
|
||||||
|
))
|
||||||
|
})?;
|
||||||
|
tracing::info!("Migrated mcp-servers.json to database");
|
||||||
|
|
||||||
|
rename_to_migrated(&mcp_path);
|
||||||
|
}
|
||||||
|
Err(e) => {
|
||||||
|
tracing::warn!("Failed to parse mcp-servers.json: {}", e);
|
||||||
|
}
|
||||||
|
},
|
||||||
|
Err(e) => {
|
||||||
|
tracing::warn!("Failed to read mcp-servers.json: {}", e);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// 4. Migrate session.json if it exists
|
||||||
|
let session_path = ironclaw_dir.join("session.json");
|
||||||
|
if session_path.exists() {
|
||||||
|
match std::fs::read_to_string(&session_path) {
|
||||||
|
Ok(content) => match serde_json::from_str::<serde_json::Value>(&content) {
|
||||||
|
Ok(value) => {
|
||||||
|
store
|
||||||
|
.set_setting(user_id, "nearai.session_token", &value)
|
||||||
|
.await
|
||||||
|
.map_err(|e| {
|
||||||
|
MigrationError::Database(format!(
|
||||||
|
"Failed to write session to DB: {}",
|
||||||
|
e
|
||||||
|
))
|
||||||
|
})?;
|
||||||
|
tracing::info!("Migrated session.json to database");
|
||||||
|
|
||||||
|
rename_to_migrated(&session_path);
|
||||||
|
}
|
||||||
|
Err(e) => {
|
||||||
|
tracing::warn!("Failed to parse session.json: {}", e);
|
||||||
|
}
|
||||||
|
},
|
||||||
|
Err(e) => {
|
||||||
|
tracing::warn!("Failed to read session.json: {}", e);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// 5. Rename settings.json to .migrated (don't delete, safety net)
|
||||||
|
rename_to_migrated(&legacy_settings_path);
|
||||||
|
|
||||||
|
// 6. Clean up old bootstrap.json if it exists (superseded by .env)
|
||||||
|
let old_bootstrap = ironclaw_dir.join("bootstrap.json");
|
||||||
|
if old_bootstrap.exists() {
|
||||||
|
rename_to_migrated(&old_bootstrap);
|
||||||
|
tracing::info!("Renamed old bootstrap.json to .migrated");
|
||||||
|
}
|
||||||
|
|
||||||
|
tracing::info!("Disk-to-DB migration complete");
|
||||||
|
Ok(())
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Rename a file to `<name>.migrated` as a safety net.
|
||||||
|
fn rename_to_migrated(path: &std::path::Path) {
|
||||||
|
let mut migrated = path.as_os_str().to_owned();
|
||||||
|
migrated.push(".migrated");
|
||||||
|
if let Err(e) = std::fs::rename(path, &migrated) {
|
||||||
|
tracing::warn!("Failed to rename {} to .migrated: {}", path.display(), e);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Errors that can occur during disk-to-DB migration.
|
||||||
|
#[derive(Debug, thiserror::Error)]
|
||||||
|
pub enum MigrationError {
|
||||||
|
#[error("Database error: {0}")]
|
||||||
|
Database(String),
|
||||||
|
#[error("IO error: {0}")]
|
||||||
|
Io(String),
|
||||||
|
}
|
||||||
|
|
||||||
|
#[cfg(test)]
|
||||||
|
mod tests {
|
||||||
|
use super::*;
|
||||||
|
use tempfile::tempdir;
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_save_and_load_database_url() {
|
||||||
|
let dir = tempdir().unwrap();
|
||||||
|
let env_path = dir.path().join(".env");
|
||||||
|
|
||||||
|
// Write in the quoted format that save_database_url uses
|
||||||
|
let url = "postgres://localhost:5432/ironclaw_test";
|
||||||
|
std::fs::write(&env_path, format!("DATABASE_URL=\"{}\"\n", url)).unwrap();
|
||||||
|
|
||||||
|
// Verify the content is a valid dotenv line (quoted)
|
||||||
|
let content = std::fs::read_to_string(&env_path).unwrap();
|
||||||
|
assert_eq!(
|
||||||
|
content,
|
||||||
|
"DATABASE_URL=\"postgres://localhost:5432/ironclaw_test\"\n"
|
||||||
|
);
|
||||||
|
|
||||||
|
// Verify dotenvy can parse it (strips quotes automatically)
|
||||||
|
let parsed: Vec<(String, String)> = dotenvy::from_path_iter(&env_path)
|
||||||
|
.unwrap()
|
||||||
|
.filter_map(|r| r.ok())
|
||||||
|
.collect();
|
||||||
|
assert_eq!(parsed.len(), 1);
|
||||||
|
assert_eq!(parsed[0].0, "DATABASE_URL");
|
||||||
|
assert_eq!(parsed[0].1, url);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_save_database_url_with_hash_in_password() {
|
||||||
|
let dir = tempdir().unwrap();
|
||||||
|
let env_path = dir.path().join(".env");
|
||||||
|
|
||||||
|
// URLs with # in the password are common (URL-encoded special chars).
|
||||||
|
// Without quoting, dotenvy treats # as a comment delimiter.
|
||||||
|
let url = "postgres://user:p%23ss@localhost:5432/ironclaw";
|
||||||
|
std::fs::write(&env_path, format!("DATABASE_URL=\"{}\"\n", url)).unwrap();
|
||||||
|
|
||||||
|
let parsed: Vec<(String, String)> = dotenvy::from_path_iter(&env_path)
|
||||||
|
.unwrap()
|
||||||
|
.filter_map(|r| r.ok())
|
||||||
|
.collect();
|
||||||
|
assert_eq!(parsed.len(), 1);
|
||||||
|
assert_eq!(parsed[0].0, "DATABASE_URL");
|
||||||
|
assert_eq!(parsed[0].1, url);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_save_database_url_creates_parent_dirs() {
|
||||||
|
let dir = tempdir().unwrap();
|
||||||
|
let nested = dir.path().join("deep").join("nested");
|
||||||
|
let env_path = nested.join(".env");
|
||||||
|
|
||||||
|
// Parent doesn't exist yet
|
||||||
|
assert!(!nested.exists());
|
||||||
|
|
||||||
|
// The global function uses a fixed path, so we test the logic directly
|
||||||
|
std::fs::create_dir_all(&nested).unwrap();
|
||||||
|
std::fs::write(&env_path, "DATABASE_URL=postgres://test\n").unwrap();
|
||||||
|
|
||||||
|
assert!(env_path.exists());
|
||||||
|
let content = std::fs::read_to_string(&env_path).unwrap();
|
||||||
|
assert!(content.contains("DATABASE_URL=postgres://test"));
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_ironclaw_env_path() {
|
||||||
|
let path = ironclaw_env_path();
|
||||||
|
assert!(path.ends_with(".ironclaw/.env"));
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_migrate_bootstrap_json_to_env() {
|
||||||
|
let dir = tempdir().unwrap();
|
||||||
|
let env_path = dir.path().join(".env");
|
||||||
|
let bootstrap_path = dir.path().join("bootstrap.json");
|
||||||
|
|
||||||
|
// Write a legacy bootstrap.json
|
||||||
|
let bootstrap_json = serde_json::json!({
|
||||||
|
"database_url": "postgres://localhost/ironclaw_upgrade",
|
||||||
|
"database_pool_size": 5,
|
||||||
|
"secrets_master_key_source": "keychain",
|
||||||
|
"onboard_completed": true
|
||||||
|
});
|
||||||
|
std::fs::write(
|
||||||
|
&bootstrap_path,
|
||||||
|
serde_json::to_string_pretty(&bootstrap_json).unwrap(),
|
||||||
|
)
|
||||||
|
.unwrap();
|
||||||
|
|
||||||
|
assert!(!env_path.exists());
|
||||||
|
assert!(bootstrap_path.exists());
|
||||||
|
|
||||||
|
// Run the migration
|
||||||
|
migrate_bootstrap_json_to_env(&env_path);
|
||||||
|
|
||||||
|
// .env should now exist with DATABASE_URL
|
||||||
|
assert!(env_path.exists());
|
||||||
|
let content = std::fs::read_to_string(&env_path).unwrap();
|
||||||
|
assert_eq!(
|
||||||
|
content,
|
||||||
|
"DATABASE_URL=\"postgres://localhost/ironclaw_upgrade\"\n"
|
||||||
|
);
|
||||||
|
|
||||||
|
// bootstrap.json should be renamed to .migrated
|
||||||
|
assert!(!bootstrap_path.exists());
|
||||||
|
assert!(dir.path().join("bootstrap.json.migrated").exists());
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_migrate_bootstrap_json_no_database_url() {
|
||||||
|
let dir = tempdir().unwrap();
|
||||||
|
let env_path = dir.path().join(".env");
|
||||||
|
let bootstrap_path = dir.path().join("bootstrap.json");
|
||||||
|
|
||||||
|
// bootstrap.json with no database_url
|
||||||
|
let bootstrap_json = serde_json::json!({
|
||||||
|
"onboard_completed": false
|
||||||
|
});
|
||||||
|
std::fs::write(
|
||||||
|
&bootstrap_path,
|
||||||
|
serde_json::to_string_pretty(&bootstrap_json).unwrap(),
|
||||||
|
)
|
||||||
|
.unwrap();
|
||||||
|
|
||||||
|
migrate_bootstrap_json_to_env(&env_path);
|
||||||
|
|
||||||
|
// .env should NOT be created
|
||||||
|
assert!(!env_path.exists());
|
||||||
|
// bootstrap.json should remain (no migration happened)
|
||||||
|
assert!(bootstrap_path.exists());
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_migrate_bootstrap_json_missing() {
|
||||||
|
let dir = tempdir().unwrap();
|
||||||
|
let env_path = dir.path().join(".env");
|
||||||
|
|
||||||
|
// No bootstrap.json at all
|
||||||
|
migrate_bootstrap_json_to_env(&env_path);
|
||||||
|
|
||||||
|
// Nothing should happen
|
||||||
|
assert!(!env_path.exists());
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_save_bootstrap_env_multiple_vars() {
|
||||||
|
let dir = tempdir().unwrap();
|
||||||
|
let env_path = dir.path().join("nested").join(".env");
|
||||||
|
|
||||||
|
std::fs::create_dir_all(env_path.parent().unwrap()).unwrap();
|
||||||
|
|
||||||
|
let vars = [
|
||||||
|
("DATABASE_BACKEND", "libsql"),
|
||||||
|
("LIBSQL_PATH", "/home/user/.ironclaw/ironclaw.db"),
|
||||||
|
];
|
||||||
|
|
||||||
|
// Write manually to the temp path (save_bootstrap_env uses the global path)
|
||||||
|
let mut content = String::new();
|
||||||
|
for (key, value) in &vars {
|
||||||
|
content.push_str(&format!("{}=\"{}\"\n", key, value));
|
||||||
|
}
|
||||||
|
std::fs::write(&env_path, &content).unwrap();
|
||||||
|
|
||||||
|
// Verify dotenvy can parse all entries
|
||||||
|
let parsed: Vec<(String, String)> = dotenvy::from_path_iter(&env_path)
|
||||||
|
.unwrap()
|
||||||
|
.filter_map(|r| r.ok())
|
||||||
|
.collect();
|
||||||
|
assert_eq!(parsed.len(), 2);
|
||||||
|
assert_eq!(
|
||||||
|
parsed[0],
|
||||||
|
("DATABASE_BACKEND".to_string(), "libsql".to_string())
|
||||||
|
);
|
||||||
|
assert_eq!(
|
||||||
|
parsed[1],
|
||||||
|
(
|
||||||
|
"LIBSQL_PATH".to_string(),
|
||||||
|
"/home/user/.ironclaw/ironclaw.db".to_string()
|
||||||
|
)
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_save_bootstrap_env_overwrites_previous() {
|
||||||
|
let dir = tempdir().unwrap();
|
||||||
|
let env_path = dir.path().join(".env");
|
||||||
|
|
||||||
|
// Write initial content
|
||||||
|
std::fs::write(&env_path, "DATABASE_URL=\"postgres://old\"\n").unwrap();
|
||||||
|
|
||||||
|
// Overwrite with new vars (simulating save_bootstrap_env behavior)
|
||||||
|
let content = "DATABASE_BACKEND=\"libsql\"\nLIBSQL_PATH=\"/new/path.db\"\n";
|
||||||
|
std::fs::write(&env_path, content).unwrap();
|
||||||
|
|
||||||
|
let parsed: Vec<(String, String)> = dotenvy::from_path_iter(&env_path)
|
||||||
|
.unwrap()
|
||||||
|
.filter_map(|r| r.ok())
|
||||||
|
.collect();
|
||||||
|
// Old DATABASE_URL should be gone
|
||||||
|
assert_eq!(parsed.len(), 2);
|
||||||
|
assert!(parsed.iter().all(|(k, _)| k != "DATABASE_URL"));
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -114,6 +114,12 @@ pub enum StatusUpdate {
|
|||||||
StreamChunk(String),
|
StreamChunk(String),
|
||||||
/// General status message.
|
/// General status message.
|
||||||
Status(String),
|
Status(String),
|
||||||
|
/// A sandbox job has started (shown as a clickable card in the UI).
|
||||||
|
JobStarted {
|
||||||
|
job_id: String,
|
||||||
|
title: String,
|
||||||
|
browse_url: String,
|
||||||
|
},
|
||||||
/// Tool requires user approval before execution.
|
/// Tool requires user approval before execution.
|
||||||
ApprovalNeeded {
|
ApprovalNeeded {
|
||||||
request_id: String,
|
request_id: String,
|
||||||
@@ -121,6 +127,19 @@ pub enum StatusUpdate {
|
|||||||
description: String,
|
description: String,
|
||||||
parameters: serde_json::Value,
|
parameters: serde_json::Value,
|
||||||
},
|
},
|
||||||
|
/// Extension needs user authentication (token or OAuth).
|
||||||
|
AuthRequired {
|
||||||
|
extension_name: String,
|
||||||
|
instructions: Option<String>,
|
||||||
|
auth_url: Option<String>,
|
||||||
|
setup_url: Option<String>,
|
||||||
|
},
|
||||||
|
/// Extension authentication completed.
|
||||||
|
AuthCompleted {
|
||||||
|
extension_name: String,
|
||||||
|
success: bool,
|
||||||
|
message: String,
|
||||||
|
},
|
||||||
}
|
}
|
||||||
|
|
||||||
/// Trait for message channels.
|
/// Trait for message channels.
|
||||||
|
|||||||
+69
-9
@@ -33,21 +33,41 @@ use termimad::MadSkin;
|
|||||||
use tokio::sync::mpsc;
|
use tokio::sync::mpsc;
|
||||||
use tokio_stream::wrappers::ReceiverStream;
|
use tokio_stream::wrappers::ReceiverStream;
|
||||||
|
|
||||||
|
use crate::agent::truncate_for_preview;
|
||||||
use crate::channels::{Channel, IncomingMessage, MessageStream, OutgoingResponse, StatusUpdate};
|
use crate::channels::{Channel, IncomingMessage, MessageStream, OutgoingResponse, StatusUpdate};
|
||||||
use crate::error::ChannelError;
|
use crate::error::ChannelError;
|
||||||
|
|
||||||
|
/// Max characters for tool result previews in the terminal.
|
||||||
|
const CLI_TOOL_RESULT_MAX: usize = 200;
|
||||||
|
|
||||||
|
/// Max characters for thinking/status messages in the terminal.
|
||||||
|
const CLI_STATUS_MAX: usize = 200;
|
||||||
|
|
||||||
/// Slash commands available in the REPL.
|
/// Slash commands available in the REPL.
|
||||||
const SLASH_COMMANDS: &[&str] = &[
|
const SLASH_COMMANDS: &[&str] = &[
|
||||||
"/help",
|
"/help",
|
||||||
"/quit",
|
"/quit",
|
||||||
"/exit",
|
"/exit",
|
||||||
"/debug",
|
"/debug",
|
||||||
|
"/model",
|
||||||
"/undo",
|
"/undo",
|
||||||
"/redo",
|
"/redo",
|
||||||
"/clear",
|
"/clear",
|
||||||
"/compact",
|
"/compact",
|
||||||
"/new",
|
"/new",
|
||||||
"/interrupt",
|
"/interrupt",
|
||||||
|
"/version",
|
||||||
|
"/tools",
|
||||||
|
"/ping",
|
||||||
|
"/job",
|
||||||
|
"/status",
|
||||||
|
"/cancel",
|
||||||
|
"/list",
|
||||||
|
"/heartbeat",
|
||||||
|
"/summarize",
|
||||||
|
"/suggest",
|
||||||
|
"/thread",
|
||||||
|
"/resume",
|
||||||
];
|
];
|
||||||
|
|
||||||
/// Rustyline helper for slash-command tab completion.
|
/// Rustyline helper for slash-command tab completion.
|
||||||
@@ -248,7 +268,7 @@ impl Channel for ReplChannel {
|
|||||||
std::thread::spawn(move || {
|
std::thread::spawn(move || {
|
||||||
// Single message mode: send it and return
|
// Single message mode: send it and return
|
||||||
if let Some(msg) = single_message {
|
if let Some(msg) = single_message {
|
||||||
let incoming = IncomingMessage::new("repl", "user", &msg);
|
let incoming = IncomingMessage::new("repl", "default", &msg);
|
||||||
let _ = tx.blocking_send(incoming);
|
let _ = tx.blocking_send(incoming);
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
@@ -295,10 +315,11 @@ impl Channel for ReplChannel {
|
|||||||
continue;
|
continue;
|
||||||
}
|
}
|
||||||
|
|
||||||
// Handle local REPL commands
|
// Handle local REPL commands (only commands that need
|
||||||
|
// immediate local handling stay here)
|
||||||
match line.to_lowercase().as_str() {
|
match line.to_lowercase().as_str() {
|
||||||
"/quit" | "/exit" => break,
|
"/quit" | "/exit" => break,
|
||||||
"/help" | "/?" => {
|
"/help" => {
|
||||||
print_help();
|
print_help();
|
||||||
continue;
|
continue;
|
||||||
}
|
}
|
||||||
@@ -315,21 +336,21 @@ impl Channel for ReplChannel {
|
|||||||
_ => {}
|
_ => {}
|
||||||
}
|
}
|
||||||
|
|
||||||
let msg = IncomingMessage::new("repl", "user", line);
|
let msg = IncomingMessage::new("repl", "default", line);
|
||||||
if tx.blocking_send(msg).is_err() {
|
if tx.blocking_send(msg).is_err() {
|
||||||
break;
|
break;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
Err(ReadlineError::Interrupted) => {
|
Err(ReadlineError::Interrupted) => {
|
||||||
// Ctrl+C: send /interrupt
|
// Ctrl+C: send /interrupt
|
||||||
let msg = IncomingMessage::new("repl", "user", "/interrupt");
|
let msg = IncomingMessage::new("repl", "default", "/interrupt");
|
||||||
if tx.blocking_send(msg).is_err() {
|
if tx.blocking_send(msg).is_err() {
|
||||||
break;
|
break;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
Err(ReadlineError::Eof) => {
|
Err(ReadlineError::Eof) => {
|
||||||
// Ctrl+D: send /quit so the agent loop runs graceful shutdown
|
// Ctrl+D: send /quit so the agent loop runs graceful shutdown
|
||||||
let msg = IncomingMessage::new("repl", "user", "/quit");
|
let msg = IncomingMessage::new("repl", "default", "/quit");
|
||||||
let _ = tx.blocking_send(msg);
|
let _ = tx.blocking_send(msg);
|
||||||
break;
|
break;
|
||||||
}
|
}
|
||||||
@@ -386,7 +407,8 @@ impl Channel for ReplChannel {
|
|||||||
|
|
||||||
match status {
|
match status {
|
||||||
StatusUpdate::Thinking(msg) => {
|
StatusUpdate::Thinking(msg) => {
|
||||||
eprintln!(" \x1b[90m\u{25CB} {msg}\x1b[0m");
|
let display = truncate_for_preview(&msg, CLI_STATUS_MAX);
|
||||||
|
eprintln!(" \x1b[90m\u{25CB} {display}\x1b[0m");
|
||||||
}
|
}
|
||||||
StatusUpdate::ToolStarted { name } => {
|
StatusUpdate::ToolStarted { name } => {
|
||||||
eprintln!(" \x1b[33m\u{25CB} {name}\x1b[0m");
|
eprintln!(" \x1b[33m\u{25CB} {name}\x1b[0m");
|
||||||
@@ -399,7 +421,8 @@ impl Channel for ReplChannel {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
StatusUpdate::ToolResult { name: _, preview } => {
|
StatusUpdate::ToolResult { name: _, preview } => {
|
||||||
eprintln!(" \x1b[90m{preview}\x1b[0m");
|
let display = truncate_for_preview(&preview, CLI_TOOL_RESULT_MAX);
|
||||||
|
eprintln!(" \x1b[90m{display}\x1b[0m");
|
||||||
}
|
}
|
||||||
StatusUpdate::StreamChunk(chunk) => {
|
StatusUpdate::StreamChunk(chunk) => {
|
||||||
// Print separator on the false-to-true transition
|
// Print separator on the false-to-true transition
|
||||||
@@ -413,9 +436,19 @@ impl Channel for ReplChannel {
|
|||||||
print!("{chunk}");
|
print!("{chunk}");
|
||||||
let _ = io::stdout().flush();
|
let _ = io::stdout().flush();
|
||||||
}
|
}
|
||||||
|
StatusUpdate::JobStarted {
|
||||||
|
job_id,
|
||||||
|
title,
|
||||||
|
browse_url,
|
||||||
|
} => {
|
||||||
|
eprintln!(
|
||||||
|
" \x1b[36m[job]\x1b[0m {title} \x1b[90m({job_id})\x1b[0m \x1b[4m{browse_url}\x1b[0m"
|
||||||
|
);
|
||||||
|
}
|
||||||
StatusUpdate::Status(msg) => {
|
StatusUpdate::Status(msg) => {
|
||||||
if debug || msg.contains("approval") || msg.contains("Approval") {
|
if debug || msg.contains("approval") || msg.contains("Approval") {
|
||||||
eprintln!(" \x1b[90m{msg}\x1b[0m");
|
let display = truncate_for_preview(&msg, CLI_STATUS_MAX);
|
||||||
|
eprintln!(" \x1b[90m{display}\x1b[0m");
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
StatusUpdate::ApprovalNeeded {
|
StatusUpdate::ApprovalNeeded {
|
||||||
@@ -472,6 +505,33 @@ impl Channel for ReplChannel {
|
|||||||
eprintln!(" {bot_border}");
|
eprintln!(" {bot_border}");
|
||||||
eprintln!();
|
eprintln!();
|
||||||
}
|
}
|
||||||
|
StatusUpdate::AuthRequired {
|
||||||
|
extension_name,
|
||||||
|
instructions,
|
||||||
|
setup_url,
|
||||||
|
..
|
||||||
|
} => {
|
||||||
|
eprintln!();
|
||||||
|
eprintln!("\x1b[33m Authentication required for {extension_name}\x1b[0m");
|
||||||
|
if let Some(ref instr) = instructions {
|
||||||
|
eprintln!(" {instr}");
|
||||||
|
}
|
||||||
|
if let Some(ref url) = setup_url {
|
||||||
|
eprintln!(" \x1b[4m{url}\x1b[0m");
|
||||||
|
}
|
||||||
|
eprintln!();
|
||||||
|
}
|
||||||
|
StatusUpdate::AuthCompleted {
|
||||||
|
extension_name,
|
||||||
|
success,
|
||||||
|
message,
|
||||||
|
} => {
|
||||||
|
if success {
|
||||||
|
eprintln!("\x1b[32m {extension_name}: {message}\x1b[0m");
|
||||||
|
} else {
|
||||||
|
eprintln!("\x1b[31m {extension_name}: {message}\x1b[0m");
|
||||||
|
}
|
||||||
|
}
|
||||||
}
|
}
|
||||||
Ok(())
|
Ok(())
|
||||||
}
|
}
|
||||||
|
|||||||
+109
-48
@@ -1,68 +1,125 @@
|
|||||||
//! Bundled WASM channels that can be installed locally.
|
//! Known WASM channels that can be installed from build artifacts.
|
||||||
|
//!
|
||||||
|
//! Instead of embedding WASM binaries in the host binary via include_bytes!,
|
||||||
|
//! channels are compiled separately and installed from their build output
|
||||||
|
//! directories during onboarding.
|
||||||
|
//!
|
||||||
|
//! Channel source layout:
|
||||||
|
//! channels-src/<name>/
|
||||||
|
//! target/wasm32-wasip2/release/<name>_channel.wasm
|
||||||
|
//! <name>.capabilities.json
|
||||||
|
|
||||||
use std::path::Path;
|
use std::path::{Path, PathBuf};
|
||||||
|
|
||||||
use tokio::fs;
|
use tokio::fs;
|
||||||
|
|
||||||
#[derive(Clone, Copy)]
|
/// Compile-time project root, used to locate channels-src/ in dev builds.
|
||||||
struct BundledChannel {
|
const CARGO_MANIFEST_DIR: &str = env!("CARGO_MANIFEST_DIR");
|
||||||
name: &'static str,
|
|
||||||
wasm: &'static [u8],
|
/// Known channel names and their crate names (for locating build artifacts).
|
||||||
capabilities: &'static [u8],
|
const KNOWN_CHANNELS: &[(&str, &str)] = &[
|
||||||
|
("telegram", "telegram_channel"),
|
||||||
|
("slack", "slack_channel"),
|
||||||
|
("whatsapp", "whatsapp_channel"),
|
||||||
|
];
|
||||||
|
|
||||||
|
/// Names of known channels that can be installed.
|
||||||
|
pub fn bundled_channel_names() -> Vec<&'static str> {
|
||||||
|
KNOWN_CHANNELS.iter().map(|(name, _)| *name).collect()
|
||||||
}
|
}
|
||||||
|
|
||||||
/// Names of bundled channels shipped with IronClaw.
|
/// Resolve the channels source directory.
|
||||||
pub fn bundled_channel_names() -> &'static [&'static str] {
|
///
|
||||||
&["telegram"]
|
/// Checks (in order):
|
||||||
|
/// 1. `IRONCLAW_CHANNELS_SRC` env var
|
||||||
|
/// 2. `<CARGO_MANIFEST_DIR>/channels-src/` (dev builds)
|
||||||
|
fn channels_src_dir() -> PathBuf {
|
||||||
|
if let Ok(dir) = std::env::var("IRONCLAW_CHANNELS_SRC") {
|
||||||
|
return PathBuf::from(dir);
|
||||||
|
}
|
||||||
|
PathBuf::from(CARGO_MANIFEST_DIR).join("channels-src")
|
||||||
}
|
}
|
||||||
|
|
||||||
/// Install a bundled channel into a channels directory.
|
/// Locate the build artifacts for a channel.
|
||||||
|
///
|
||||||
|
/// Returns (wasm_path, capabilities_path) or an error if files are missing.
|
||||||
|
fn locate_channel_artifacts(name: &str) -> Result<(PathBuf, PathBuf), String> {
|
||||||
|
let (_, crate_name) = KNOWN_CHANNELS
|
||||||
|
.iter()
|
||||||
|
.find(|(n, _)| *n == name)
|
||||||
|
.ok_or_else(|| format!("Unknown channel '{}'", name))?;
|
||||||
|
|
||||||
|
let src_dir = channels_src_dir();
|
||||||
|
let channel_dir = src_dir.join(name);
|
||||||
|
|
||||||
|
let wasm_path = channel_dir
|
||||||
|
.join("target/wasm32-wasip2/release")
|
||||||
|
.join(format!("{}.wasm", crate_name));
|
||||||
|
|
||||||
|
let caps_path = channel_dir.join(format!("{}.capabilities.json", name));
|
||||||
|
|
||||||
|
if !wasm_path.exists() {
|
||||||
|
return Err(format!(
|
||||||
|
"Channel '{}' WASM not found at {}. Build it first:\n \
|
||||||
|
cd {} && cargo build --target wasm32-wasip2 --release",
|
||||||
|
name,
|
||||||
|
wasm_path.display(),
|
||||||
|
channel_dir.display()
|
||||||
|
));
|
||||||
|
}
|
||||||
|
|
||||||
|
if !caps_path.exists() {
|
||||||
|
return Err(format!(
|
||||||
|
"Channel '{}' capabilities not found at {}",
|
||||||
|
name,
|
||||||
|
caps_path.display()
|
||||||
|
));
|
||||||
|
}
|
||||||
|
|
||||||
|
Ok((wasm_path, caps_path))
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Install a channel from build artifacts into the channels directory.
|
||||||
pub async fn install_bundled_channel(
|
pub async fn install_bundled_channel(
|
||||||
name: &str,
|
name: &str,
|
||||||
target_dir: &Path,
|
target_dir: &Path,
|
||||||
force: bool,
|
force: bool,
|
||||||
) -> Result<(), String> {
|
) -> Result<(), String> {
|
||||||
let channel = bundled_channel(name)
|
let (wasm_src, caps_src) = locate_channel_artifacts(name)?;
|
||||||
.ok_or_else(|| format!("Unknown bundled channel '{}'", name.to_lowercase()))?;
|
|
||||||
|
|
||||||
fs::create_dir_all(target_dir)
|
fs::create_dir_all(target_dir)
|
||||||
.await
|
.await
|
||||||
.map_err(|e| format!("Failed to create channels directory: {}", e))?;
|
.map_err(|e| format!("Failed to create channels directory: {}", e))?;
|
||||||
|
|
||||||
let wasm_path = target_dir.join(format!("{}.wasm", channel.name));
|
let wasm_dst = target_dir.join(format!("{}.wasm", name));
|
||||||
let caps_path = target_dir.join(format!("{}.capabilities.json", channel.name));
|
let caps_dst = target_dir.join(format!("{}.capabilities.json", name));
|
||||||
|
|
||||||
let has_existing = wasm_path.exists() || caps_path.exists();
|
let has_existing = wasm_dst.exists() || caps_dst.exists();
|
||||||
if has_existing && !force {
|
if has_existing && !force {
|
||||||
return Err(format!(
|
return Err(format!(
|
||||||
"Channel '{}' already exists at {}",
|
"Channel '{}' already exists at {}",
|
||||||
channel.name,
|
name,
|
||||||
target_dir.display()
|
target_dir.display()
|
||||||
));
|
));
|
||||||
}
|
}
|
||||||
|
|
||||||
fs::write(&wasm_path, channel.wasm)
|
fs::copy(&wasm_src, &wasm_dst)
|
||||||
.await
|
.await
|
||||||
.map_err(|e| format!("Failed to write {}: {}", wasm_path.display(), e))?;
|
.map_err(|e| format!("Failed to copy {}: {}", wasm_src.display(), e))?;
|
||||||
fs::write(&caps_path, channel.capabilities)
|
fs::copy(&caps_src, &caps_dst)
|
||||||
.await
|
.await
|
||||||
.map_err(|e| format!("Failed to write {}: {}", caps_path.display(), e))?;
|
.map_err(|e| format!("Failed to copy {}: {}", caps_src.display(), e))?;
|
||||||
|
|
||||||
Ok(())
|
Ok(())
|
||||||
}
|
}
|
||||||
|
|
||||||
fn bundled_channel(name: &str) -> Option<BundledChannel> {
|
/// Check which known channels have build artifacts available.
|
||||||
if name.eq_ignore_ascii_case("telegram") {
|
pub fn available_channel_names() -> Vec<&'static str> {
|
||||||
Some(BundledChannel {
|
KNOWN_CHANNELS
|
||||||
name: "telegram",
|
.iter()
|
||||||
wasm: include_bytes!("../../../channels-src/telegram/telegram.wasm"),
|
.filter(|(name, _)| locate_channel_artifacts(name).is_ok())
|
||||||
capabilities: include_bytes!(
|
.map(|(name, _)| *name)
|
||||||
"../../../channels-src/telegram/telegram.capabilities.json"
|
.collect()
|
||||||
),
|
|
||||||
})
|
|
||||||
} else {
|
|
||||||
None
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
#[cfg(test)]
|
#[cfg(test)]
|
||||||
@@ -73,31 +130,35 @@ mod tests {
|
|||||||
use super::*;
|
use super::*;
|
||||||
|
|
||||||
#[test]
|
#[test]
|
||||||
fn test_bundled_channel_names_contains_telegram() {
|
fn test_known_channels_includes_all_three() {
|
||||||
assert!(bundled_channel_names().contains(&"telegram"));
|
let names = bundled_channel_names();
|
||||||
|
assert!(names.contains(&"telegram"));
|
||||||
|
assert!(names.contains(&"slack"));
|
||||||
|
assert!(names.contains(&"whatsapp"));
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_channels_src_dir_default() {
|
||||||
|
let dir = channels_src_dir();
|
||||||
|
assert!(dir.ends_with("channels-src"));
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_locate_unknown_channel_errors() {
|
||||||
|
assert!(locate_channel_artifacts("nonexistent").is_err());
|
||||||
}
|
}
|
||||||
|
|
||||||
#[tokio::test]
|
#[tokio::test]
|
||||||
async fn test_install_bundled_channel_writes_files() {
|
async fn test_install_refuses_overwrite_without_force() {
|
||||||
let dir = tempdir().unwrap();
|
|
||||||
|
|
||||||
install_bundled_channel("telegram", dir.path(), false)
|
|
||||||
.await
|
|
||||||
.unwrap();
|
|
||||||
|
|
||||||
assert!(dir.path().join("telegram.wasm").exists());
|
|
||||||
assert!(dir.path().join("telegram.capabilities.json").exists());
|
|
||||||
}
|
|
||||||
|
|
||||||
#[tokio::test]
|
|
||||||
async fn test_install_bundled_channel_refuses_overwrite_without_force() {
|
|
||||||
let dir = tempdir().unwrap();
|
let dir = tempdir().unwrap();
|
||||||
let wasm_path = dir.path().join("telegram.wasm");
|
let wasm_path = dir.path().join("telegram.wasm");
|
||||||
fs::write(&wasm_path, b"custom").await.unwrap();
|
fs::write(&wasm_path, b"custom").await.unwrap();
|
||||||
|
|
||||||
let result = install_bundled_channel("telegram", dir.path(), false).await;
|
let result = install_bundled_channel("telegram", dir.path(), false).await;
|
||||||
|
// Either fails because artifacts missing OR because file exists
|
||||||
assert!(result.is_err());
|
assert!(result.is_err());
|
||||||
|
|
||||||
|
// Original file should be untouched
|
||||||
let existing = fs::read(&wasm_path).await.unwrap();
|
let existing = fs::read(&wasm_path).await.unwrap();
|
||||||
assert_eq!(existing, b"custom");
|
assert_eq!(existing, b"custom");
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -16,16 +16,21 @@ use crate::channels::wasm::error::WasmChannelError;
|
|||||||
use crate::channels::wasm::runtime::WasmChannelRuntime;
|
use crate::channels::wasm::runtime::WasmChannelRuntime;
|
||||||
use crate::channels::wasm::schema::ChannelCapabilitiesFile;
|
use crate::channels::wasm::schema::ChannelCapabilitiesFile;
|
||||||
use crate::channels::wasm::wrapper::WasmChannel;
|
use crate::channels::wasm::wrapper::WasmChannel;
|
||||||
|
use crate::pairing::PairingStore;
|
||||||
|
|
||||||
/// Loads WASM channels from the filesystem.
|
/// Loads WASM channels from the filesystem.
|
||||||
pub struct WasmChannelLoader {
|
pub struct WasmChannelLoader {
|
||||||
runtime: Arc<WasmChannelRuntime>,
|
runtime: Arc<WasmChannelRuntime>,
|
||||||
|
pairing_store: Arc<PairingStore>,
|
||||||
}
|
}
|
||||||
|
|
||||||
impl WasmChannelLoader {
|
impl WasmChannelLoader {
|
||||||
/// Create a new loader with the given runtime.
|
/// Create a new loader with the given runtime and pairing store.
|
||||||
pub fn new(runtime: Arc<WasmChannelRuntime>) -> Self {
|
pub fn new(runtime: Arc<WasmChannelRuntime>, pairing_store: Arc<PairingStore>) -> Self {
|
||||||
Self { runtime }
|
Self {
|
||||||
|
runtime,
|
||||||
|
pairing_store,
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
/// Load a single WASM channel from a file pair.
|
/// Load a single WASM channel from a file pair.
|
||||||
@@ -114,7 +119,13 @@ impl WasmChannelLoader {
|
|||||||
.await?;
|
.await?;
|
||||||
|
|
||||||
// Create the channel
|
// Create the channel
|
||||||
let channel = WasmChannel::new(self.runtime.clone(), prepared, capabilities, config_json);
|
let channel = WasmChannel::new(
|
||||||
|
self.runtime.clone(),
|
||||||
|
prepared,
|
||||||
|
capabilities,
|
||||||
|
config_json,
|
||||||
|
self.pairing_store.clone(),
|
||||||
|
);
|
||||||
|
|
||||||
tracing::info!(
|
tracing::info!(
|
||||||
name = name,
|
name = name,
|
||||||
@@ -352,6 +363,7 @@ mod tests {
|
|||||||
|
|
||||||
use crate::channels::wasm::loader::{WasmChannelLoader, discover_channels};
|
use crate::channels::wasm::loader::{WasmChannelLoader, discover_channels};
|
||||||
use crate::channels::wasm::runtime::{WasmChannelRuntime, WasmChannelRuntimeConfig};
|
use crate::channels::wasm::runtime::{WasmChannelRuntime, WasmChannelRuntimeConfig};
|
||||||
|
use crate::pairing::PairingStore;
|
||||||
use std::sync::Arc;
|
use std::sync::Arc;
|
||||||
|
|
||||||
#[tokio::test]
|
#[tokio::test]
|
||||||
@@ -408,7 +420,7 @@ mod tests {
|
|||||||
async fn test_loader_invalid_name() {
|
async fn test_loader_invalid_name() {
|
||||||
let config = WasmChannelRuntimeConfig::for_testing();
|
let config = WasmChannelRuntimeConfig::for_testing();
|
||||||
let runtime = Arc::new(WasmChannelRuntime::new(config).unwrap());
|
let runtime = Arc::new(WasmChannelRuntime::new(config).unwrap());
|
||||||
let loader = WasmChannelLoader::new(runtime);
|
let loader = WasmChannelLoader::new(runtime, Arc::new(PairingStore::new()));
|
||||||
|
|
||||||
let dir = TempDir::new().unwrap();
|
let dir = TempDir::new().unwrap();
|
||||||
let wasm_path = dir.path().join("test.wasm");
|
let wasm_path = dir.path().join("test.wasm");
|
||||||
|
|||||||
@@ -89,7 +89,7 @@ mod schema;
|
|||||||
mod wrapper;
|
mod wrapper;
|
||||||
|
|
||||||
// Core types
|
// Core types
|
||||||
pub use bundled::{bundled_channel_names, install_bundled_channel};
|
pub use bundled::{available_channel_names, bundled_channel_names, install_bundled_channel};
|
||||||
pub use capabilities::{ChannelCapabilities, EmitRateLimitConfig, HttpEndpointConfig, PollConfig};
|
pub use capabilities::{ChannelCapabilities, EmitRateLimitConfig, HttpEndpointConfig, PollConfig};
|
||||||
pub use error::WasmChannelError;
|
pub use error::WasmChannelError;
|
||||||
pub use host::{ChannelEmitRateLimiter, ChannelHostState, EmittedMessage};
|
pub use host::{ChannelEmitRateLimiter, ChannelHostState, EmittedMessage};
|
||||||
|
|||||||
@@ -478,6 +478,7 @@ mod tests {
|
|||||||
PreparedChannelModule, WasmChannelRuntime, WasmChannelRuntimeConfig,
|
PreparedChannelModule, WasmChannelRuntime, WasmChannelRuntimeConfig,
|
||||||
};
|
};
|
||||||
use crate::channels::wasm::wrapper::WasmChannel;
|
use crate::channels::wasm::wrapper::WasmChannel;
|
||||||
|
use crate::pairing::PairingStore;
|
||||||
use crate::tools::wasm::ResourceLimits;
|
use crate::tools::wasm::ResourceLimits;
|
||||||
|
|
||||||
fn create_test_channel(name: &str) -> Arc<WasmChannel> {
|
fn create_test_channel(name: &str) -> Arc<WasmChannel> {
|
||||||
@@ -499,6 +500,7 @@ mod tests {
|
|||||||
prepared,
|
prepared,
|
||||||
capabilities,
|
capabilities,
|
||||||
"{}".to_string(),
|
"{}".to_string(),
|
||||||
|
Arc::new(PairingStore::new()),
|
||||||
))
|
))
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
+383
-37
@@ -48,6 +48,7 @@ use crate::channels::wasm::runtime::{PreparedChannelModule, WasmChannelRuntime};
|
|||||||
use crate::channels::wasm::schema::ChannelConfig;
|
use crate::channels::wasm::schema::ChannelConfig;
|
||||||
use crate::channels::{Channel, IncomingMessage, MessageStream, OutgoingResponse, StatusUpdate};
|
use crate::channels::{Channel, IncomingMessage, MessageStream, OutgoingResponse, StatusUpdate};
|
||||||
use crate::error::ChannelError;
|
use crate::error::ChannelError;
|
||||||
|
use crate::pairing::PairingStore;
|
||||||
use crate::safety::LeakDetector;
|
use crate::safety::LeakDetector;
|
||||||
use crate::tools::wasm::LogLevel;
|
use crate::tools::wasm::LogLevel;
|
||||||
use crate::tools::wasm::WasmResourceLimiter;
|
use crate::tools::wasm::WasmResourceLimiter;
|
||||||
@@ -73,6 +74,11 @@ struct ChannelStoreData {
|
|||||||
/// Injected credentials for URL substitution (e.g., bot tokens).
|
/// Injected credentials for URL substitution (e.g., bot tokens).
|
||||||
/// Keys are placeholder names like "TELEGRAM_BOT_TOKEN".
|
/// Keys are placeholder names like "TELEGRAM_BOT_TOKEN".
|
||||||
credentials: HashMap<String, String>,
|
credentials: HashMap<String, String>,
|
||||||
|
/// Pairing store for DM pairing (guest access control).
|
||||||
|
pairing_store: Arc<PairingStore>,
|
||||||
|
/// Dedicated tokio runtime for HTTP requests, lazily initialized.
|
||||||
|
/// Reused across multiple `http_request` calls within one execution.
|
||||||
|
http_runtime: Option<tokio::runtime::Runtime>,
|
||||||
}
|
}
|
||||||
|
|
||||||
impl ChannelStoreData {
|
impl ChannelStoreData {
|
||||||
@@ -81,6 +87,7 @@ impl ChannelStoreData {
|
|||||||
channel_name: &str,
|
channel_name: &str,
|
||||||
capabilities: ChannelCapabilities,
|
capabilities: ChannelCapabilities,
|
||||||
credentials: HashMap<String, String>,
|
credentials: HashMap<String, String>,
|
||||||
|
pairing_store: Arc<PairingStore>,
|
||||||
) -> Self {
|
) -> Self {
|
||||||
// Create a minimal WASI context (no filesystem, no env vars for security)
|
// Create a minimal WASI context (no filesystem, no env vars for security)
|
||||||
let wasi = WasiCtxBuilder::new().build();
|
let wasi = WasiCtxBuilder::new().build();
|
||||||
@@ -91,6 +98,8 @@ impl ChannelStoreData {
|
|||||||
wasi,
|
wasi,
|
||||||
table: ResourceTable::new(),
|
table: ResourceTable::new(),
|
||||||
credentials,
|
credentials,
|
||||||
|
pairing_store,
|
||||||
|
http_runtime: None,
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -129,16 +138,32 @@ impl ChannelStoreData {
|
|||||||
if result.contains('{') && result.contains('}') {
|
if result.contains('{') && result.contains('}') {
|
||||||
// Only warn if it looks like an unresolved placeholder (not JSON braces)
|
// Only warn if it looks like an unresolved placeholder (not JSON braces)
|
||||||
let brace_pattern = regex::Regex::new(r"\{[A-Z_]+\}").ok();
|
let brace_pattern = regex::Regex::new(r"\{[A-Z_]+\}").ok();
|
||||||
if let Some(re) = brace_pattern {
|
if let Some(re) = brace_pattern
|
||||||
if re.is_match(&result) {
|
&& re.is_match(&result)
|
||||||
|
{
|
||||||
tracing::warn!(
|
tracing::warn!(
|
||||||
context = %context,
|
context = %context,
|
||||||
"String may contain unresolved credential placeholders"
|
"String may contain unresolved credential placeholders"
|
||||||
);
|
);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
result
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/// Replace injected credential values with `[REDACTED]` in text.
|
||||||
|
///
|
||||||
|
/// Prevents credentials from leaking through error messages, logs, or
|
||||||
|
/// return values to WASM. reqwest::Error includes the full URL in its
|
||||||
|
/// Display output, so any error from an injected-URL request will
|
||||||
|
/// contain the raw credential unless we scrub it.
|
||||||
|
fn redact_credentials(&self, text: &str) -> String {
|
||||||
|
let mut result = text.to_string();
|
||||||
|
for (name, value) in &self.credentials {
|
||||||
|
if !value.is_empty() {
|
||||||
|
result = result.replace(value, &format!("[REDACTED:{}]", name));
|
||||||
|
}
|
||||||
|
}
|
||||||
result
|
result
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -187,6 +212,7 @@ impl near::agent::channel_host::Host for ChannelStoreData {
|
|||||||
url: String,
|
url: String,
|
||||||
headers_json: String,
|
headers_json: String,
|
||||||
body: Option<Vec<u8>>,
|
body: Option<Vec<u8>>,
|
||||||
|
timeout_ms: Option<u32>,
|
||||||
) -> Result<near::agent::channel_host::HttpResponse, String> {
|
) -> Result<near::agent::channel_host::HttpResponse, String> {
|
||||||
tracing::info!(
|
tracing::info!(
|
||||||
method = %method,
|
method = %method,
|
||||||
@@ -251,10 +277,35 @@ impl near::agent::channel_host::Host for ChannelStoreData {
|
|||||||
.scan_http_request(&url, &header_vec, body.as_deref())
|
.scan_http_request(&url, &header_vec, body.as_deref())
|
||||||
.map_err(|e| format!("Potential secret leak blocked: {}", e))?;
|
.map_err(|e| format!("Potential secret leak blocked: {}", e))?;
|
||||||
|
|
||||||
// Make the HTTP request using blocking I/O
|
// Get the max response size from capabilities (default 10MB).
|
||||||
// We're already in a spawn_blocking context, so we can use block_on
|
let max_response_bytes = self
|
||||||
let result = tokio::runtime::Handle::current().block_on(async {
|
.host_state
|
||||||
let client = reqwest::Client::new();
|
.capabilities()
|
||||||
|
.tool_capabilities
|
||||||
|
.http
|
||||||
|
.as_ref()
|
||||||
|
.map(|h| h.max_response_bytes)
|
||||||
|
.unwrap_or(10 * 1024 * 1024);
|
||||||
|
|
||||||
|
// Make the HTTP request using a dedicated single-threaded runtime.
|
||||||
|
// We're inside spawn_blocking, so we can't rely on the main runtime's
|
||||||
|
// I/O driver (it may be busy with WASM compilation or other startup work).
|
||||||
|
// A dedicated runtime gives us our own I/O driver and avoids contention.
|
||||||
|
// The runtime is lazily created and reused across calls within one execution.
|
||||||
|
if self.http_runtime.is_none() {
|
||||||
|
self.http_runtime = Some(
|
||||||
|
tokio::runtime::Builder::new_current_thread()
|
||||||
|
.enable_all()
|
||||||
|
.build()
|
||||||
|
.map_err(|e| format!("Failed to create HTTP runtime: {e}"))?,
|
||||||
|
);
|
||||||
|
}
|
||||||
|
let rt = self.http_runtime.as_ref().expect("just initialized");
|
||||||
|
let result = rt.block_on(async {
|
||||||
|
let client = reqwest::Client::builder()
|
||||||
|
.connect_timeout(std::time::Duration::from_secs(10))
|
||||||
|
.build()
|
||||||
|
.map_err(|e| format!("Failed to build HTTP client: {e}"))?;
|
||||||
|
|
||||||
let mut request = match method.to_uppercase().as_str() {
|
let mut request = match method.to_uppercase().as_str() {
|
||||||
"GET" => client.get(&url),
|
"GET" => client.get(&url),
|
||||||
@@ -276,12 +327,21 @@ impl near::agent::channel_host::Host for ChannelStoreData {
|
|||||||
request = request.body(body_bytes);
|
request = request.body(body_bytes);
|
||||||
}
|
}
|
||||||
|
|
||||||
// Send request with timeout
|
// Send request with caller-specified timeout (default 30s, max 5min).
|
||||||
let response = request
|
let timeout_ms = timeout_ms.unwrap_or(30_000).min(300_000) as u64;
|
||||||
.timeout(std::time::Duration::from_secs(30))
|
let timeout = std::time::Duration::from_millis(timeout_ms);
|
||||||
.send()
|
let response = request.timeout(timeout).send().await.map_err(|e| {
|
||||||
.await
|
// Walk the full error chain so we get the actual root cause
|
||||||
.map_err(|e| format!("HTTP request failed: {}", e))?;
|
// (DNS, TLS, connection refused, etc.) instead of just
|
||||||
|
// "error sending request for url (...)".
|
||||||
|
let mut chain = format!("HTTP request failed: {}", e);
|
||||||
|
let mut source = std::error::Error::source(&e);
|
||||||
|
while let Some(cause) = source {
|
||||||
|
chain.push_str(&format!(" -> {}", cause));
|
||||||
|
source = cause.source();
|
||||||
|
}
|
||||||
|
chain
|
||||||
|
})?;
|
||||||
|
|
||||||
let status = response.status().as_u16();
|
let status = response.status().as_u16();
|
||||||
let response_headers: std::collections::HashMap<String, String> = response
|
let response_headers: std::collections::HashMap<String, String> = response
|
||||||
@@ -294,11 +354,29 @@ impl near::agent::channel_host::Host for ChannelStoreData {
|
|||||||
})
|
})
|
||||||
.collect();
|
.collect();
|
||||||
let headers_json = serde_json::to_string(&response_headers).unwrap_or_default();
|
let headers_json = serde_json::to_string(&response_headers).unwrap_or_default();
|
||||||
|
|
||||||
|
// Enforce max response body size to prevent memory exhaustion.
|
||||||
|
let max_response = max_response_bytes;
|
||||||
|
if let Some(cl) = response.content_length()
|
||||||
|
&& cl as usize > max_response
|
||||||
|
{
|
||||||
|
return Err(format!(
|
||||||
|
"Response body too large: {} bytes exceeds limit of {} bytes",
|
||||||
|
cl, max_response
|
||||||
|
));
|
||||||
|
}
|
||||||
let body = response
|
let body = response
|
||||||
.bytes()
|
.bytes()
|
||||||
.await
|
.await
|
||||||
.map_err(|e| format!("Failed to read response body: {}", e))?
|
.map_err(|e| format!("Failed to read response body: {}", e))?;
|
||||||
.to_vec();
|
if body.len() > max_response {
|
||||||
|
return Err(format!(
|
||||||
|
"Response body too large: {} bytes exceeds limit of {} bytes",
|
||||||
|
body.len(),
|
||||||
|
max_response
|
||||||
|
));
|
||||||
|
}
|
||||||
|
let body = body.to_vec();
|
||||||
|
|
||||||
tracing::info!(
|
tracing::info!(
|
||||||
status = status,
|
status = status,
|
||||||
@@ -330,6 +408,11 @@ impl near::agent::channel_host::Host for ChannelStoreData {
|
|||||||
})
|
})
|
||||||
});
|
});
|
||||||
|
|
||||||
|
// Scrub credential values from error messages before logging or returning
|
||||||
|
// to WASM. reqwest::Error includes the full URL (with injected credentials)
|
||||||
|
// in its Display output.
|
||||||
|
let result = result.map_err(|e| self.redact_credentials(&e));
|
||||||
|
|
||||||
match &result {
|
match &result {
|
||||||
Ok(resp) => {
|
Ok(resp) => {
|
||||||
tracing::info!(status = resp.status, "http_request completed successfully");
|
tracing::info!(status = resp.status, "http_request completed successfully");
|
||||||
@@ -372,6 +455,43 @@ impl near::agent::channel_host::Host for ChannelStoreData {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
fn pairing_upsert_request(
|
||||||
|
&mut self,
|
||||||
|
channel: String,
|
||||||
|
id: String,
|
||||||
|
meta_json: String,
|
||||||
|
) -> Result<near::agent::channel_host::PairingUpsertResult, String> {
|
||||||
|
let meta = if meta_json.is_empty() {
|
||||||
|
None
|
||||||
|
} else {
|
||||||
|
serde_json::from_str(&meta_json).ok()
|
||||||
|
};
|
||||||
|
match self.pairing_store.upsert_request(&channel, &id, meta) {
|
||||||
|
Ok(r) => Ok(near::agent::channel_host::PairingUpsertResult {
|
||||||
|
code: r.code,
|
||||||
|
created: r.created,
|
||||||
|
}),
|
||||||
|
Err(e) => Err(e.to_string()),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
fn pairing_is_allowed(
|
||||||
|
&mut self,
|
||||||
|
channel: String,
|
||||||
|
id: String,
|
||||||
|
username: Option<String>,
|
||||||
|
) -> Result<bool, String> {
|
||||||
|
self.pairing_store
|
||||||
|
.is_sender_allowed(&channel, &id, username.as_deref())
|
||||||
|
.map_err(|e| e.to_string())
|
||||||
|
}
|
||||||
|
|
||||||
|
fn pairing_read_allow_from(&mut self, channel: String) -> Result<Vec<String>, String> {
|
||||||
|
self.pairing_store
|
||||||
|
.read_allow_from(&channel)
|
||||||
|
.map_err(|e| e.to_string())
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
/// A WASM-based channel implementing the Channel trait.
|
/// A WASM-based channel implementing the Channel trait.
|
||||||
@@ -424,6 +544,9 @@ pub struct WasmChannel {
|
|||||||
/// Background task that repeats typing indicators every 4 seconds.
|
/// Background task that repeats typing indicators every 4 seconds.
|
||||||
/// Telegram's "typing..." indicator expires after ~5s, so we refresh it.
|
/// Telegram's "typing..." indicator expires after ~5s, so we refresh it.
|
||||||
typing_task: RwLock<Option<tokio::task::JoinHandle<()>>>,
|
typing_task: RwLock<Option<tokio::task::JoinHandle<()>>>,
|
||||||
|
|
||||||
|
/// Pairing store for DM pairing (guest access control).
|
||||||
|
pairing_store: Arc<PairingStore>,
|
||||||
}
|
}
|
||||||
|
|
||||||
impl WasmChannel {
|
impl WasmChannel {
|
||||||
@@ -433,6 +556,7 @@ impl WasmChannel {
|
|||||||
prepared: Arc<PreparedChannelModule>,
|
prepared: Arc<PreparedChannelModule>,
|
||||||
capabilities: ChannelCapabilities,
|
capabilities: ChannelCapabilities,
|
||||||
config_json: String,
|
config_json: String,
|
||||||
|
pairing_store: Arc<PairingStore>,
|
||||||
) -> Self {
|
) -> Self {
|
||||||
let name = prepared.name.clone();
|
let name = prepared.name.clone();
|
||||||
let rate_limiter = ChannelEmitRateLimiter::new(capabilities.emit_rate_limit.clone());
|
let rate_limiter = ChannelEmitRateLimiter::new(capabilities.emit_rate_limit.clone());
|
||||||
@@ -452,6 +576,7 @@ impl WasmChannel {
|
|||||||
endpoints: RwLock::new(Vec::new()),
|
endpoints: RwLock::new(Vec::new()),
|
||||||
credentials: Arc::new(RwLock::new(HashMap::new())),
|
credentials: Arc::new(RwLock::new(HashMap::new())),
|
||||||
typing_task: RwLock::new(None),
|
typing_task: RwLock::new(None),
|
||||||
|
pairing_store,
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -533,6 +658,7 @@ impl WasmChannel {
|
|||||||
prepared: &PreparedChannelModule,
|
prepared: &PreparedChannelModule,
|
||||||
capabilities: &ChannelCapabilities,
|
capabilities: &ChannelCapabilities,
|
||||||
credentials: HashMap<String, String>,
|
credentials: HashMap<String, String>,
|
||||||
|
pairing_store: Arc<PairingStore>,
|
||||||
) -> Result<Store<ChannelStoreData>, WasmChannelError> {
|
) -> Result<Store<ChannelStoreData>, WasmChannelError> {
|
||||||
let engine = runtime.engine();
|
let engine = runtime.engine();
|
||||||
let limits = &prepared.limits;
|
let limits = &prepared.limits;
|
||||||
@@ -543,6 +669,7 @@ impl WasmChannel {
|
|||||||
&prepared.name,
|
&prepared.name,
|
||||||
capabilities.clone(),
|
capabilities.clone(),
|
||||||
credentials,
|
credentials,
|
||||||
|
pairing_store,
|
||||||
);
|
);
|
||||||
let mut store = Store::new(engine, store_data);
|
let mut store = Store::new(engine, store_data);
|
||||||
|
|
||||||
@@ -643,12 +770,18 @@ impl WasmChannel {
|
|||||||
let timeout = self.runtime.config().callback_timeout;
|
let timeout = self.runtime.config().callback_timeout;
|
||||||
let channel_name = self.name.clone();
|
let channel_name = self.name.clone();
|
||||||
let credentials = self.get_credentials().await;
|
let credentials = self.get_credentials().await;
|
||||||
|
let pairing_store = self.pairing_store.clone();
|
||||||
|
|
||||||
// Execute in blocking task with timeout
|
// Execute in blocking task with timeout
|
||||||
let result = tokio::time::timeout(timeout, async move {
|
let result = tokio::time::timeout(timeout, async move {
|
||||||
tokio::task::spawn_blocking(move || {
|
tokio::task::spawn_blocking(move || {
|
||||||
let mut store =
|
let mut store = Self::create_store(
|
||||||
Self::create_store(&runtime, &prepared, &capabilities, credentials)?;
|
&runtime,
|
||||||
|
&prepared,
|
||||||
|
&capabilities,
|
||||||
|
credentials,
|
||||||
|
pairing_store,
|
||||||
|
)?;
|
||||||
let instance = Self::instantiate_component(&runtime, &prepared, &mut store)?;
|
let instance = Self::instantiate_component(&runtime, &prepared, &mut store)?;
|
||||||
|
|
||||||
// Call on_start using the generated typed interface
|
// Call on_start using the generated typed interface
|
||||||
@@ -681,7 +814,21 @@ impl WasmChannel {
|
|||||||
.await;
|
.await;
|
||||||
|
|
||||||
match result {
|
match result {
|
||||||
Ok(Ok((config, _host_state))) => {
|
Ok(Ok((config, mut host_state))) => {
|
||||||
|
// Surface WASM guest logs (errors/warnings from webhook setup, etc.)
|
||||||
|
for entry in host_state.take_logs() {
|
||||||
|
match entry.level {
|
||||||
|
crate::tools::wasm::LogLevel::Error => {
|
||||||
|
tracing::error!(channel = %self.name, "{}", entry.message);
|
||||||
|
}
|
||||||
|
crate::tools::wasm::LogLevel::Warn => {
|
||||||
|
tracing::warn!(channel = %self.name, "{}", entry.message);
|
||||||
|
}
|
||||||
|
_ => {
|
||||||
|
tracing::debug!(channel = %self.name, "{}", entry.message);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
tracing::info!(
|
tracing::info!(
|
||||||
channel = %self.name,
|
channel = %self.name,
|
||||||
display_name = %config.display_name,
|
display_name = %config.display_name,
|
||||||
@@ -753,6 +900,7 @@ impl WasmChannel {
|
|||||||
let capabilities = self.capabilities.clone();
|
let capabilities = self.capabilities.clone();
|
||||||
let timeout = self.runtime.config().callback_timeout;
|
let timeout = self.runtime.config().callback_timeout;
|
||||||
let credentials = self.get_credentials().await;
|
let credentials = self.get_credentials().await;
|
||||||
|
let pairing_store = self.pairing_store.clone();
|
||||||
|
|
||||||
// Prepare request data
|
// Prepare request data
|
||||||
let method = method.to_string();
|
let method = method.to_string();
|
||||||
@@ -766,8 +914,13 @@ impl WasmChannel {
|
|||||||
// Execute in blocking task with timeout
|
// Execute in blocking task with timeout
|
||||||
let result = tokio::time::timeout(timeout, async move {
|
let result = tokio::time::timeout(timeout, async move {
|
||||||
tokio::task::spawn_blocking(move || {
|
tokio::task::spawn_blocking(move || {
|
||||||
let mut store =
|
let mut store = Self::create_store(
|
||||||
Self::create_store(&runtime, &prepared, &capabilities, credentials)?;
|
&runtime,
|
||||||
|
&prepared,
|
||||||
|
&capabilities,
|
||||||
|
credentials,
|
||||||
|
pairing_store,
|
||||||
|
)?;
|
||||||
let instance = Self::instantiate_component(&runtime, &prepared, &mut store)?;
|
let instance = Self::instantiate_component(&runtime, &prepared, &mut store)?;
|
||||||
|
|
||||||
// Build the WIT request type
|
// Build the WIT request type
|
||||||
@@ -840,12 +993,18 @@ impl WasmChannel {
|
|||||||
let timeout = self.runtime.config().callback_timeout;
|
let timeout = self.runtime.config().callback_timeout;
|
||||||
let channel_name = self.name.clone();
|
let channel_name = self.name.clone();
|
||||||
let credentials = self.get_credentials().await;
|
let credentials = self.get_credentials().await;
|
||||||
|
let pairing_store = self.pairing_store.clone();
|
||||||
|
|
||||||
// Execute in blocking task with timeout
|
// Execute in blocking task with timeout
|
||||||
let result = tokio::time::timeout(timeout, async move {
|
let result = tokio::time::timeout(timeout, async move {
|
||||||
tokio::task::spawn_blocking(move || {
|
tokio::task::spawn_blocking(move || {
|
||||||
let mut store =
|
let mut store = Self::create_store(
|
||||||
Self::create_store(&runtime, &prepared, &capabilities, credentials)?;
|
&runtime,
|
||||||
|
&prepared,
|
||||||
|
&capabilities,
|
||||||
|
credentials,
|
||||||
|
pairing_store,
|
||||||
|
)?;
|
||||||
let instance = Self::instantiate_component(&runtime, &prepared, &mut store)?;
|
let instance = Self::instantiate_component(&runtime, &prepared, &mut store)?;
|
||||||
|
|
||||||
// Call on_poll using the generated typed interface
|
// Call on_poll using the generated typed interface
|
||||||
@@ -929,6 +1088,7 @@ impl WasmChannel {
|
|||||||
let timeout = self.runtime.config().callback_timeout;
|
let timeout = self.runtime.config().callback_timeout;
|
||||||
let channel_name = self.name.clone();
|
let channel_name = self.name.clone();
|
||||||
let credentials = self.get_credentials().await;
|
let credentials = self.get_credentials().await;
|
||||||
|
let pairing_store = self.pairing_store.clone();
|
||||||
|
|
||||||
// Prepare response data
|
// Prepare response data
|
||||||
let message_id_str = message_id.to_string();
|
let message_id_str = message_id.to_string();
|
||||||
@@ -942,8 +1102,13 @@ impl WasmChannel {
|
|||||||
let result = tokio::time::timeout(timeout, async move {
|
let result = tokio::time::timeout(timeout, async move {
|
||||||
tokio::task::spawn_blocking(move || {
|
tokio::task::spawn_blocking(move || {
|
||||||
tracing::info!("Creating WASM store for on_respond");
|
tracing::info!("Creating WASM store for on_respond");
|
||||||
let mut store =
|
let mut store = Self::create_store(
|
||||||
Self::create_store(&runtime, &prepared, &capabilities, credentials)?;
|
&runtime,
|
||||||
|
&prepared,
|
||||||
|
&capabilities,
|
||||||
|
credentials,
|
||||||
|
pairing_store,
|
||||||
|
)?;
|
||||||
|
|
||||||
tracing::info!("Instantiating WASM component for on_respond");
|
tracing::info!("Instantiating WASM component for on_respond");
|
||||||
let instance = Self::instantiate_component(&runtime, &prepared, &mut store)?;
|
let instance = Self::instantiate_component(&runtime, &prepared, &mut store)?;
|
||||||
@@ -1036,13 +1201,19 @@ impl WasmChannel {
|
|||||||
let timeout = self.runtime.config().callback_timeout;
|
let timeout = self.runtime.config().callback_timeout;
|
||||||
let channel_name = self.name.clone();
|
let channel_name = self.name.clone();
|
||||||
let credentials = self.get_credentials().await;
|
let credentials = self.get_credentials().await;
|
||||||
|
let pairing_store = self.pairing_store.clone();
|
||||||
|
|
||||||
let wit_update = status_to_wit(status, metadata);
|
let wit_update = status_to_wit(status, metadata);
|
||||||
|
|
||||||
let result = tokio::time::timeout(timeout, async move {
|
let result = tokio::time::timeout(timeout, async move {
|
||||||
tokio::task::spawn_blocking(move || {
|
tokio::task::spawn_blocking(move || {
|
||||||
let mut store =
|
let mut store = Self::create_store(
|
||||||
Self::create_store(&runtime, &prepared, &capabilities, credentials)?;
|
&runtime,
|
||||||
|
&prepared,
|
||||||
|
&capabilities,
|
||||||
|
credentials,
|
||||||
|
pairing_store,
|
||||||
|
)?;
|
||||||
let instance = Self::instantiate_component(&runtime, &prepared, &mut store)?;
|
let instance = Self::instantiate_component(&runtime, &prepared, &mut store)?;
|
||||||
|
|
||||||
let channel_iface = instance.near_agent_channel();
|
let channel_iface = instance.near_agent_channel();
|
||||||
@@ -1080,12 +1251,14 @@ impl WasmChannel {
|
|||||||
///
|
///
|
||||||
/// Static method for use by the background typing repeat task (which
|
/// Static method for use by the background typing repeat task (which
|
||||||
/// doesn't have access to `&self`).
|
/// doesn't have access to `&self`).
|
||||||
|
#[allow(clippy::too_many_arguments)]
|
||||||
async fn execute_status(
|
async fn execute_status(
|
||||||
channel_name: &str,
|
channel_name: &str,
|
||||||
runtime: &Arc<WasmChannelRuntime>,
|
runtime: &Arc<WasmChannelRuntime>,
|
||||||
prepared: &Arc<PreparedChannelModule>,
|
prepared: &Arc<PreparedChannelModule>,
|
||||||
capabilities: &ChannelCapabilities,
|
capabilities: &ChannelCapabilities,
|
||||||
credentials: &RwLock<HashMap<String, String>>,
|
credentials: &RwLock<HashMap<String, String>>,
|
||||||
|
pairing_store: Arc<PairingStore>,
|
||||||
timeout: Duration,
|
timeout: Duration,
|
||||||
wit_update: wit_channel::StatusUpdate,
|
wit_update: wit_channel::StatusUpdate,
|
||||||
) -> Result<(), WasmChannelError> {
|
) -> Result<(), WasmChannelError> {
|
||||||
@@ -1101,8 +1274,13 @@ impl WasmChannel {
|
|||||||
|
|
||||||
let result = tokio::time::timeout(timeout, async move {
|
let result = tokio::time::timeout(timeout, async move {
|
||||||
tokio::task::spawn_blocking(move || {
|
tokio::task::spawn_blocking(move || {
|
||||||
let mut store =
|
let mut store = Self::create_store(
|
||||||
Self::create_store(&runtime, &prepared, &capabilities, credentials_snapshot)?;
|
&runtime,
|
||||||
|
&prepared,
|
||||||
|
&capabilities,
|
||||||
|
credentials_snapshot,
|
||||||
|
pairing_store,
|
||||||
|
)?;
|
||||||
let instance = Self::instantiate_component(&runtime, &prepared, &mut store)?;
|
let instance = Self::instantiate_component(&runtime, &prepared, &mut store)?;
|
||||||
|
|
||||||
let channel_iface = instance.near_agent_channel();
|
let channel_iface = instance.near_agent_channel();
|
||||||
@@ -1170,6 +1348,7 @@ impl WasmChannel {
|
|||||||
let prepared = Arc::clone(&self.prepared);
|
let prepared = Arc::clone(&self.prepared);
|
||||||
let capabilities = self.capabilities.clone();
|
let capabilities = self.capabilities.clone();
|
||||||
let credentials = self.credentials.clone();
|
let credentials = self.credentials.clone();
|
||||||
|
let pairing_store = self.pairing_store.clone();
|
||||||
let callback_timeout = self.runtime.config().callback_timeout;
|
let callback_timeout = self.runtime.config().callback_timeout;
|
||||||
let wit_update = status_to_wit(&status, metadata);
|
let wit_update = status_to_wit(&status, metadata);
|
||||||
|
|
||||||
@@ -1189,6 +1368,7 @@ impl WasmChannel {
|
|||||||
&prepared,
|
&prepared,
|
||||||
&capabilities,
|
&capabilities,
|
||||||
&credentials,
|
&credentials,
|
||||||
|
pairing_store.clone(),
|
||||||
callback_timeout,
|
callback_timeout,
|
||||||
wit_update_clone,
|
wit_update_clone,
|
||||||
)
|
)
|
||||||
@@ -1319,6 +1499,7 @@ impl WasmChannel {
|
|||||||
let message_tx = self.message_tx.clone();
|
let message_tx = self.message_tx.clone();
|
||||||
let rate_limiter = self.rate_limiter.clone();
|
let rate_limiter = self.rate_limiter.clone();
|
||||||
let credentials = self.credentials.clone();
|
let credentials = self.credentials.clone();
|
||||||
|
let pairing_store = self.pairing_store.clone();
|
||||||
let callback_timeout = self.runtime.config().callback_timeout;
|
let callback_timeout = self.runtime.config().callback_timeout;
|
||||||
|
|
||||||
tokio::spawn(async move {
|
tokio::spawn(async move {
|
||||||
@@ -1340,14 +1521,15 @@ impl WasmChannel {
|
|||||||
&prepared,
|
&prepared,
|
||||||
&capabilities,
|
&capabilities,
|
||||||
&credentials,
|
&credentials,
|
||||||
|
pairing_store.clone(),
|
||||||
callback_timeout,
|
callback_timeout,
|
||||||
).await;
|
).await;
|
||||||
|
|
||||||
match result {
|
match result {
|
||||||
Ok(emitted_messages) => {
|
Ok(emitted_messages) => {
|
||||||
// Process any emitted messages
|
// Process any emitted messages
|
||||||
if !emitted_messages.is_empty() {
|
if !emitted_messages.is_empty()
|
||||||
if let Err(e) = Self::dispatch_emitted_messages(
|
&& let Err(e) = Self::dispatch_emitted_messages(
|
||||||
&channel_name,
|
&channel_name,
|
||||||
emitted_messages,
|
emitted_messages,
|
||||||
&message_tx,
|
&message_tx,
|
||||||
@@ -1360,7 +1542,6 @@ impl WasmChannel {
|
|||||||
);
|
);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
|
||||||
Err(e) => {
|
Err(e) => {
|
||||||
tracing::warn!(
|
tracing::warn!(
|
||||||
channel = %channel_name,
|
channel = %channel_name,
|
||||||
@@ -1391,6 +1572,7 @@ impl WasmChannel {
|
|||||||
prepared: &Arc<PreparedChannelModule>,
|
prepared: &Arc<PreparedChannelModule>,
|
||||||
capabilities: &ChannelCapabilities,
|
capabilities: &ChannelCapabilities,
|
||||||
credentials: &RwLock<HashMap<String, String>>,
|
credentials: &RwLock<HashMap<String, String>>,
|
||||||
|
pairing_store: Arc<PairingStore>,
|
||||||
timeout: Duration,
|
timeout: Duration,
|
||||||
) -> Result<Vec<EmittedMessage>, WasmChannelError> {
|
) -> Result<Vec<EmittedMessage>, WasmChannelError> {
|
||||||
// Skip if no WASM bytes (testing mode)
|
// Skip if no WASM bytes (testing mode)
|
||||||
@@ -1411,8 +1593,13 @@ impl WasmChannel {
|
|||||||
// Execute in blocking task with timeout
|
// Execute in blocking task with timeout
|
||||||
let result = tokio::time::timeout(timeout, async move {
|
let result = tokio::time::timeout(timeout, async move {
|
||||||
tokio::task::spawn_blocking(move || {
|
tokio::task::spawn_blocking(move || {
|
||||||
let mut store =
|
let mut store = Self::create_store(
|
||||||
Self::create_store(&runtime, &prepared, &capabilities, credentials_snapshot)?;
|
&runtime,
|
||||||
|
&prepared,
|
||||||
|
&capabilities,
|
||||||
|
credentials_snapshot,
|
||||||
|
pairing_store,
|
||||||
|
)?;
|
||||||
let instance = Self::instantiate_component(&runtime, &prepared, &mut store)?;
|
let instance = Self::instantiate_component(&runtime, &prepared, &mut store)?;
|
||||||
|
|
||||||
// Call on_poll using the generated typed interface
|
// Call on_poll using the generated typed interface
|
||||||
@@ -1583,8 +1770,9 @@ impl Channel for WasmChannel {
|
|||||||
*self.endpoints.write().await = endpoints;
|
*self.endpoints.write().await = endpoints;
|
||||||
|
|
||||||
// Start polling if configured
|
// Start polling if configured
|
||||||
if let Some(poll_config) = &config.poll {
|
if let Some(poll_config) = &config.poll
|
||||||
if poll_config.enabled {
|
&& poll_config.enabled
|
||||||
|
{
|
||||||
let interval = self
|
let interval = self
|
||||||
.capabilities
|
.capabilities
|
||||||
.validate_poll_interval(poll_config.interval_ms)
|
.validate_poll_interval(poll_config.interval_ms)
|
||||||
@@ -1599,7 +1787,6 @@ impl Channel for WasmChannel {
|
|||||||
|
|
||||||
self.start_polling(Duration::from_millis(interval as u64), poll_shutdown_rx);
|
self.start_polling(Duration::from_millis(interval as u64), poll_shutdown_rx);
|
||||||
}
|
}
|
||||||
}
|
|
||||||
|
|
||||||
tracing::info!(
|
tracing::info!(
|
||||||
channel = %self.name,
|
channel = %self.name,
|
||||||
@@ -1858,6 +2045,29 @@ fn status_to_wit(status: &StatusUpdate, metadata: &serde_json::Value) -> wit_cha
|
|||||||
message: format!("Approval needed: {} - {}", tool_name, description),
|
message: format!("Approval needed: {} - {}", tool_name, description),
|
||||||
metadata_json,
|
metadata_json,
|
||||||
},
|
},
|
||||||
|
StatusUpdate::JobStarted { job_id, title, .. } => wit_channel::StatusUpdate {
|
||||||
|
status: wit_channel::StatusType::Thinking,
|
||||||
|
message: format!("Job started: {} ({})", title, job_id),
|
||||||
|
metadata_json,
|
||||||
|
},
|
||||||
|
StatusUpdate::AuthRequired { extension_name, .. } => wit_channel::StatusUpdate {
|
||||||
|
status: wit_channel::StatusType::Thinking,
|
||||||
|
message: format!("Auth required: {}", extension_name),
|
||||||
|
metadata_json,
|
||||||
|
},
|
||||||
|
StatusUpdate::AuthCompleted {
|
||||||
|
extension_name,
|
||||||
|
success,
|
||||||
|
..
|
||||||
|
} => wit_channel::StatusUpdate {
|
||||||
|
status: wit_channel::StatusType::Thinking,
|
||||||
|
message: format!(
|
||||||
|
"Auth {}: {}",
|
||||||
|
if *success { "completed" } else { "failed" },
|
||||||
|
extension_name
|
||||||
|
),
|
||||||
|
metadata_json,
|
||||||
|
},
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -1929,6 +2139,7 @@ mod tests {
|
|||||||
PreparedChannelModule, WasmChannelRuntime, WasmChannelRuntimeConfig,
|
PreparedChannelModule, WasmChannelRuntime, WasmChannelRuntimeConfig,
|
||||||
};
|
};
|
||||||
use crate::channels::wasm::wrapper::{HttpResponse, WasmChannel};
|
use crate::channels::wasm::wrapper::{HttpResponse, WasmChannel};
|
||||||
|
use crate::pairing::PairingStore;
|
||||||
use crate::tools::wasm::ResourceLimits;
|
use crate::tools::wasm::ResourceLimits;
|
||||||
|
|
||||||
fn create_test_channel() -> WasmChannel {
|
fn create_test_channel() -> WasmChannel {
|
||||||
@@ -1944,7 +2155,13 @@ mod tests {
|
|||||||
|
|
||||||
let capabilities = ChannelCapabilities::for_channel("test").with_path("/webhook/test");
|
let capabilities = ChannelCapabilities::for_channel("test").with_path("/webhook/test");
|
||||||
|
|
||||||
WasmChannel::new(runtime, prepared, capabilities, "{}".to_string())
|
WasmChannel::new(
|
||||||
|
runtime,
|
||||||
|
prepared,
|
||||||
|
capabilities,
|
||||||
|
"{}".to_string(),
|
||||||
|
Arc::new(PairingStore::new()),
|
||||||
|
)
|
||||||
}
|
}
|
||||||
|
|
||||||
#[test]
|
#[test]
|
||||||
@@ -2019,6 +2236,7 @@ mod tests {
|
|||||||
&prepared,
|
&prepared,
|
||||||
&capabilities,
|
&capabilities,
|
||||||
&credentials,
|
&credentials,
|
||||||
|
Arc::new(PairingStore::new()),
|
||||||
timeout,
|
timeout,
|
||||||
)
|
)
|
||||||
.await;
|
.await;
|
||||||
@@ -2112,7 +2330,13 @@ mod tests {
|
|||||||
.with_path("/webhook/poll")
|
.with_path("/webhook/poll")
|
||||||
.with_polling(1000);
|
.with_polling(1000);
|
||||||
|
|
||||||
let channel = WasmChannel::new(runtime, prepared, capabilities, "{}".to_string());
|
let channel = WasmChannel::new(
|
||||||
|
runtime,
|
||||||
|
prepared,
|
||||||
|
capabilities,
|
||||||
|
"{}".to_string(),
|
||||||
|
Arc::new(PairingStore::new()),
|
||||||
|
);
|
||||||
|
|
||||||
// Start the channel
|
// Start the channel
|
||||||
let _stream = channel.start().await.expect("Channel should start");
|
let _stream = channel.start().await.expect("Channel should start");
|
||||||
@@ -2350,4 +2574,126 @@ mod tests {
|
|||||||
assert_eq!(cloned.message, "hello");
|
assert_eq!(cloned.message, "hello");
|
||||||
assert_eq!(cloned.metadata_json, "{\"a\":1}");
|
assert_eq!(cloned.metadata_json, "{\"a\":1}");
|
||||||
}
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_redact_credentials_replaces_values() {
|
||||||
|
use super::ChannelStoreData;
|
||||||
|
|
||||||
|
let mut creds = std::collections::HashMap::new();
|
||||||
|
creds.insert(
|
||||||
|
"TELEGRAM_BOT_TOKEN".to_string(),
|
||||||
|
"8218490433:AAEZeUxwqZ5OO3mOCXv7fKvpdhDgsmBBNis".to_string(),
|
||||||
|
);
|
||||||
|
creds.insert("OTHER_SECRET".to_string(), "s3cret".to_string());
|
||||||
|
|
||||||
|
let store = ChannelStoreData::new(
|
||||||
|
1024 * 1024,
|
||||||
|
"test",
|
||||||
|
ChannelCapabilities::default(),
|
||||||
|
creds,
|
||||||
|
Arc::new(PairingStore::new()),
|
||||||
|
);
|
||||||
|
|
||||||
|
let error = "HTTP request failed: error sending request for url \
|
||||||
|
(https://api.telegram.org/bot8218490433:AAEZeUxwqZ5OO3mOCXv7fKvpdhDgsmBBNis/getUpdates)";
|
||||||
|
|
||||||
|
let redacted = store.redact_credentials(error);
|
||||||
|
|
||||||
|
assert!(
|
||||||
|
!redacted.contains("8218490433:AAEZeUxwqZ5OO3mOCXv7fKvpdhDgsmBBNis"),
|
||||||
|
"credential value should be redacted"
|
||||||
|
);
|
||||||
|
assert!(
|
||||||
|
redacted.contains("[REDACTED:TELEGRAM_BOT_TOKEN]"),
|
||||||
|
"redacted text should contain placeholder name"
|
||||||
|
);
|
||||||
|
assert!(
|
||||||
|
!redacted.contains("s3cret"),
|
||||||
|
"other credentials should also be redacted"
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_redact_credentials_no_op_without_credentials() {
|
||||||
|
use super::ChannelStoreData;
|
||||||
|
|
||||||
|
let store = ChannelStoreData::new(
|
||||||
|
1024 * 1024,
|
||||||
|
"test",
|
||||||
|
ChannelCapabilities::default(),
|
||||||
|
std::collections::HashMap::new(),
|
||||||
|
Arc::new(PairingStore::new()),
|
||||||
|
);
|
||||||
|
|
||||||
|
let input = "some error message";
|
||||||
|
assert_eq!(store.redact_credentials(input), input);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_redact_credentials_skips_empty_values() {
|
||||||
|
use super::ChannelStoreData;
|
||||||
|
|
||||||
|
let mut creds = std::collections::HashMap::new();
|
||||||
|
creds.insert("EMPTY_TOKEN".to_string(), String::new());
|
||||||
|
|
||||||
|
let store = ChannelStoreData::new(
|
||||||
|
1024 * 1024,
|
||||||
|
"test",
|
||||||
|
ChannelCapabilities::default(),
|
||||||
|
creds,
|
||||||
|
Arc::new(PairingStore::new()),
|
||||||
|
);
|
||||||
|
|
||||||
|
let input = "should not match anything";
|
||||||
|
assert_eq!(store.redact_credentials(input), input);
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Verify that WASM HTTP host functions work using a dedicated
|
||||||
|
/// current-thread runtime inside spawn_blocking.
|
||||||
|
#[tokio::test]
|
||||||
|
async fn test_dedicated_runtime_inside_spawn_blocking() {
|
||||||
|
let result = tokio::task::spawn_blocking(|| {
|
||||||
|
let rt = tokio::runtime::Builder::new_current_thread()
|
||||||
|
.enable_all()
|
||||||
|
.build()
|
||||||
|
.expect("failed to build runtime");
|
||||||
|
rt.block_on(async { 42 })
|
||||||
|
})
|
||||||
|
.await
|
||||||
|
.expect("spawn_blocking panicked");
|
||||||
|
assert_eq!(result, 42);
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Verify a real HTTP request works using the dedicated-runtime pattern.
|
||||||
|
/// This catches DNS, TLS, and I/O driver issues that trivial tests miss.
|
||||||
|
#[tokio::test]
|
||||||
|
#[ignore] // requires network
|
||||||
|
async fn test_dedicated_runtime_real_http() {
|
||||||
|
let result = tokio::task::spawn_blocking(|| {
|
||||||
|
let rt = tokio::runtime::Builder::new_current_thread()
|
||||||
|
.enable_all()
|
||||||
|
.build()
|
||||||
|
.expect("failed to build runtime");
|
||||||
|
rt.block_on(async {
|
||||||
|
let client = reqwest::Client::builder()
|
||||||
|
.connect_timeout(std::time::Duration::from_secs(10))
|
||||||
|
.build()
|
||||||
|
.expect("failed to build client");
|
||||||
|
let resp = client
|
||||||
|
.get("https://api.telegram.org/bot000/getMe")
|
||||||
|
.timeout(std::time::Duration::from_secs(10))
|
||||||
|
.send()
|
||||||
|
.await;
|
||||||
|
match resp {
|
||||||
|
Ok(r) => r.status().as_u16(),
|
||||||
|
Err(e) if e.is_timeout() => panic!("request timed out: {e}"),
|
||||||
|
Err(e) => panic!("unexpected error: {e}"),
|
||||||
|
}
|
||||||
|
})
|
||||||
|
})
|
||||||
|
.await
|
||||||
|
.expect("spawn_blocking panicked");
|
||||||
|
// 404 because "000" is not a valid bot token
|
||||||
|
assert_eq!(result, 404);
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
+11
-12
@@ -6,6 +6,7 @@ use axum::{
|
|||||||
middleware::Next,
|
middleware::Next,
|
||||||
response::{IntoResponse, Response},
|
response::{IntoResponse, Response},
|
||||||
};
|
};
|
||||||
|
use subtle::ConstantTimeEq;
|
||||||
|
|
||||||
/// Shared auth state injected via axum middleware state.
|
/// Shared auth state injected via axum middleware state.
|
||||||
#[derive(Clone)]
|
#[derive(Clone)]
|
||||||
@@ -23,27 +24,25 @@ pub async fn auth_middleware(
|
|||||||
request: Request,
|
request: Request,
|
||||||
next: Next,
|
next: Next,
|
||||||
) -> Response {
|
) -> Response {
|
||||||
// Try Authorization header first
|
// Try Authorization header first (constant-time comparison)
|
||||||
if let Some(auth_header) = headers.get("authorization") {
|
if let Some(auth_header) = headers.get("authorization")
|
||||||
if let Ok(value) = auth_header.to_str() {
|
&& let Ok(value) = auth_header.to_str()
|
||||||
if let Some(token) = value.strip_prefix("Bearer ") {
|
&& let Some(token) = value.strip_prefix("Bearer ")
|
||||||
if token == auth.token {
|
&& bool::from(token.as_bytes().ct_eq(auth.token.as_bytes()))
|
||||||
|
{
|
||||||
return next.run(request).await;
|
return next.run(request).await;
|
||||||
}
|
}
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// Fall back to query parameter (for SSE EventSource)
|
// Fall back to query parameter for SSE EventSource (constant-time comparison)
|
||||||
if let Some(query) = request.uri().query() {
|
if let Some(query) = request.uri().query() {
|
||||||
for pair in query.split('&') {
|
for pair in query.split('&') {
|
||||||
if let Some(token) = pair.strip_prefix("token=") {
|
if let Some(token) = pair.strip_prefix("token=")
|
||||||
if token == auth.token {
|
&& bool::from(token.as_bytes().ct_eq(auth.token.as_bytes()))
|
||||||
|
{
|
||||||
return next.run(request).await;
|
return next.run(request).await;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
|
||||||
|
|
||||||
(StatusCode::UNAUTHORIZED, "Invalid or missing auth token").into_response()
|
(StatusCode::UNAUTHORIZED, "Invalid or missing auth token").into_response()
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -24,6 +24,8 @@ use tokio::sync::broadcast;
|
|||||||
use tracing::field::{Field, Visit};
|
use tracing::field::{Field, Visit};
|
||||||
use tracing_subscriber::Layer;
|
use tracing_subscriber::Layer;
|
||||||
|
|
||||||
|
use crate::safety::LeakDetector;
|
||||||
|
|
||||||
/// Maximum number of recent log entries kept for late-joining SSE subscribers.
|
/// Maximum number of recent log entries kept for late-joining SSE subscribers.
|
||||||
const HISTORY_CAP: usize = 500;
|
const HISTORY_CAP: usize = 500;
|
||||||
|
|
||||||
@@ -46,6 +48,8 @@ pub struct LogEntry {
|
|||||||
pub struct LogBroadcaster {
|
pub struct LogBroadcaster {
|
||||||
tx: broadcast::Sender<LogEntry>,
|
tx: broadcast::Sender<LogEntry>,
|
||||||
recent: Mutex<VecDeque<LogEntry>>,
|
recent: Mutex<VecDeque<LogEntry>>,
|
||||||
|
/// Scrubs secrets from log messages before broadcasting to SSE clients.
|
||||||
|
leak_detector: LeakDetector,
|
||||||
}
|
}
|
||||||
|
|
||||||
impl LogBroadcaster {
|
impl LogBroadcaster {
|
||||||
@@ -54,10 +58,19 @@ impl LogBroadcaster {
|
|||||||
Self {
|
Self {
|
||||||
tx,
|
tx,
|
||||||
recent: Mutex::new(VecDeque::with_capacity(HISTORY_CAP)),
|
recent: Mutex::new(VecDeque::with_capacity(HISTORY_CAP)),
|
||||||
|
leak_detector: LeakDetector::new(),
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
pub fn send(&self, entry: LogEntry) {
|
pub fn send(&self, mut entry: LogEntry) {
|
||||||
|
// Scrub secrets from the message before it reaches any subscriber.
|
||||||
|
// This is defense-in-depth: even if code elsewhere accidentally logs
|
||||||
|
// a secret, it won't be broadcast to SSE clients.
|
||||||
|
entry.message = self
|
||||||
|
.leak_detector
|
||||||
|
.scan_and_clean(&entry.message)
|
||||||
|
.unwrap_or_else(|_| "[log message redacted: contained blocked secret]".to_string());
|
||||||
|
|
||||||
// Stash in ring buffer (for late joiners)
|
// Stash in ring buffer (for late joiners)
|
||||||
if let Ok(mut buf) = self.recent.lock() {
|
if let Ok(mut buf) = self.recent.lock() {
|
||||||
if buf.len() >= HISTORY_CAP {
|
if buf.len() >= HISTORY_CAP {
|
||||||
@@ -145,6 +158,9 @@ impl Visit for MessageVisitor {
|
|||||||
///
|
///
|
||||||
/// Only forwards DEBUG and above. Attach to the tracing subscriber
|
/// Only forwards DEBUG and above. Attach to the tracing subscriber
|
||||||
/// alongside the existing fmt layer.
|
/// alongside the existing fmt layer.
|
||||||
|
///
|
||||||
|
/// Log messages are scrubbed through `LeakDetector` in `LogBroadcaster::send()`
|
||||||
|
/// (the single funnel point for all log output, including late-joiner history).
|
||||||
pub struct WebLogLayer {
|
pub struct WebLogLayer {
|
||||||
broadcaster: Arc<LogBroadcaster>,
|
broadcaster: Arc<LogBroadcaster>,
|
||||||
}
|
}
|
||||||
@@ -178,6 +194,7 @@ impl<S: tracing::Subscriber> Layer<S> for WebLogLayer {
|
|||||||
timestamp: chrono::Utc::now().to_rfc3339_opts(chrono::SecondsFormat::Millis, true),
|
timestamp: chrono::Utc::now().to_rfc3339_opts(chrono::SecondsFormat::Millis, true),
|
||||||
};
|
};
|
||||||
|
|
||||||
|
// LeakDetector scrubbing happens inside broadcaster.send()
|
||||||
self.broadcaster.send(entry);
|
self.broadcaster.send(entry);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -313,4 +330,29 @@ mod tests {
|
|||||||
let v = MessageVisitor::new();
|
let v = MessageVisitor::new();
|
||||||
assert_eq!(v.finish(), "");
|
assert_eq!(v.finish(), "");
|
||||||
}
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_broadcaster_has_leak_detector() {
|
||||||
|
let broadcaster = LogBroadcaster::new();
|
||||||
|
// Verify the leak detector is initialized with default patterns
|
||||||
|
assert!(broadcaster.leak_detector.pattern_count() > 0);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_leak_detector_scrubs_api_key_in_log() {
|
||||||
|
let detector = crate::safety::LeakDetector::new();
|
||||||
|
let msg = "Connecting with token sk-proj-test1234567890abcdefghij";
|
||||||
|
let result = detector.scan_and_clean(msg);
|
||||||
|
// Should be blocked (OpenAI key pattern)
|
||||||
|
assert!(result.is_err());
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_leak_detector_passes_clean_log() {
|
||||||
|
let detector = crate::safety::LeakDetector::new();
|
||||||
|
let msg = "Request completed status=200 url=https://api.example.com/data";
|
||||||
|
let result = detector.scan_and_clean(msg);
|
||||||
|
assert!(result.is_ok());
|
||||||
|
assert_eq!(result.unwrap(), msg);
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
+108
-23
@@ -10,12 +10,13 @@
|
|||||||
//! ◄── GET /api/chat/events ── SSE stream
|
//! ◄── GET /api/chat/events ── SSE stream
|
||||||
//! ─── GET /api/chat/ws ─────► WebSocket (bidirectional)
|
//! ─── GET /api/chat/ws ─────► WebSocket (bidirectional)
|
||||||
//! ─── GET /api/memory/* ────► Workspace
|
//! ─── GET /api/memory/* ────► Workspace
|
||||||
//! ─── GET /api/jobs/* ──────► ContextManager
|
//! ─── GET /api/jobs/* ──────► Database
|
||||||
//! ◄── GET / ───────────────── Static HTML/CSS/JS
|
//! ◄── GET / ───────────────── Static HTML/CSS/JS
|
||||||
//! ```
|
//! ```
|
||||||
|
|
||||||
pub mod auth;
|
pub mod auth;
|
||||||
pub mod log_layer;
|
pub mod log_layer;
|
||||||
|
pub mod openai_compat;
|
||||||
pub mod server;
|
pub mod server;
|
||||||
pub mod sse;
|
pub mod sse;
|
||||||
pub mod types;
|
pub mod types;
|
||||||
@@ -31,9 +32,10 @@ use tokio_stream::wrappers::ReceiverStream;
|
|||||||
use crate::agent::SessionManager;
|
use crate::agent::SessionManager;
|
||||||
use crate::channels::{Channel, IncomingMessage, MessageStream, OutgoingResponse, StatusUpdate};
|
use crate::channels::{Channel, IncomingMessage, MessageStream, OutgoingResponse, StatusUpdate};
|
||||||
use crate::config::GatewayConfig;
|
use crate::config::GatewayConfig;
|
||||||
use crate::context::ContextManager;
|
use crate::db::Database;
|
||||||
use crate::error::ChannelError;
|
use crate::error::ChannelError;
|
||||||
use crate::extensions::ExtensionManager;
|
use crate::extensions::ExtensionManager;
|
||||||
|
use crate::orchestrator::job_manager::ContainerJobManager;
|
||||||
use crate::tools::ToolRegistry;
|
use crate::tools::ToolRegistry;
|
||||||
use crate::workspace::Workspace;
|
use crate::workspace::Workspace;
|
||||||
|
|
||||||
@@ -70,14 +72,18 @@ impl GatewayChannel {
|
|||||||
msg_tx: tokio::sync::RwLock::new(None),
|
msg_tx: tokio::sync::RwLock::new(None),
|
||||||
sse: SseManager::new(),
|
sse: SseManager::new(),
|
||||||
workspace: None,
|
workspace: None,
|
||||||
context_manager: None,
|
|
||||||
session_manager: None,
|
session_manager: None,
|
||||||
log_broadcaster: None,
|
log_broadcaster: None,
|
||||||
extension_manager: None,
|
extension_manager: None,
|
||||||
tool_registry: None,
|
tool_registry: None,
|
||||||
|
store: None,
|
||||||
|
job_manager: None,
|
||||||
|
prompt_queue: None,
|
||||||
user_id: config.user_id.clone(),
|
user_id: config.user_id.clone(),
|
||||||
shutdown_tx: tokio::sync::RwLock::new(None),
|
shutdown_tx: tokio::sync::RwLock::new(None),
|
||||||
ws_tracker: Some(Arc::new(ws::WsConnectionTracker::new())),
|
ws_tracker: Some(Arc::new(ws::WsConnectionTracker::new())),
|
||||||
|
llm_provider: None,
|
||||||
|
chat_rate_limiter: server::RateLimiter::new(30, 60),
|
||||||
});
|
});
|
||||||
|
|
||||||
Self {
|
Self {
|
||||||
@@ -93,14 +99,18 @@ impl GatewayChannel {
|
|||||||
msg_tx: tokio::sync::RwLock::new(None),
|
msg_tx: tokio::sync::RwLock::new(None),
|
||||||
sse: SseManager::new(),
|
sse: SseManager::new(),
|
||||||
workspace: self.state.workspace.clone(),
|
workspace: self.state.workspace.clone(),
|
||||||
context_manager: self.state.context_manager.clone(),
|
|
||||||
session_manager: self.state.session_manager.clone(),
|
session_manager: self.state.session_manager.clone(),
|
||||||
log_broadcaster: self.state.log_broadcaster.clone(),
|
log_broadcaster: self.state.log_broadcaster.clone(),
|
||||||
extension_manager: self.state.extension_manager.clone(),
|
extension_manager: self.state.extension_manager.clone(),
|
||||||
tool_registry: self.state.tool_registry.clone(),
|
tool_registry: self.state.tool_registry.clone(),
|
||||||
|
store: self.state.store.clone(),
|
||||||
|
job_manager: self.state.job_manager.clone(),
|
||||||
|
prompt_queue: self.state.prompt_queue.clone(),
|
||||||
user_id: self.state.user_id.clone(),
|
user_id: self.state.user_id.clone(),
|
||||||
shutdown_tx: tokio::sync::RwLock::new(None),
|
shutdown_tx: tokio::sync::RwLock::new(None),
|
||||||
ws_tracker: self.state.ws_tracker.clone(),
|
ws_tracker: self.state.ws_tracker.clone(),
|
||||||
|
llm_provider: self.state.llm_provider.clone(),
|
||||||
|
chat_rate_limiter: server::RateLimiter::new(30, 60),
|
||||||
};
|
};
|
||||||
mutate(&mut new_state);
|
mutate(&mut new_state);
|
||||||
self.state = Arc::new(new_state);
|
self.state = Arc::new(new_state);
|
||||||
@@ -112,12 +122,6 @@ impl GatewayChannel {
|
|||||||
self
|
self
|
||||||
}
|
}
|
||||||
|
|
||||||
/// Inject the context manager for the jobs API.
|
|
||||||
pub fn with_context_manager(mut self, cm: Arc<ContextManager>) -> Self {
|
|
||||||
self.rebuild_state(|s| s.context_manager = Some(cm));
|
|
||||||
self
|
|
||||||
}
|
|
||||||
|
|
||||||
/// Inject the session manager for thread/session info.
|
/// Inject the session manager for thread/session info.
|
||||||
pub fn with_session_manager(mut self, sm: Arc<SessionManager>) -> Self {
|
pub fn with_session_manager(mut self, sm: Arc<SessionManager>) -> Self {
|
||||||
self.rebuild_state(|s| s.session_manager = Some(sm));
|
self.rebuild_state(|s| s.session_manager = Some(sm));
|
||||||
@@ -142,6 +146,40 @@ impl GatewayChannel {
|
|||||||
self
|
self
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/// Inject the database store for sandbox job persistence.
|
||||||
|
pub fn with_store(mut self, store: Arc<dyn Database>) -> Self {
|
||||||
|
self.rebuild_state(|s| s.store = Some(store));
|
||||||
|
self
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Inject the container job manager for sandbox operations.
|
||||||
|
pub fn with_job_manager(mut self, jm: Arc<ContainerJobManager>) -> Self {
|
||||||
|
self.rebuild_state(|s| s.job_manager = Some(jm));
|
||||||
|
self
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Inject the prompt queue for Claude Code follow-up prompts.
|
||||||
|
pub fn with_prompt_queue(
|
||||||
|
mut self,
|
||||||
|
pq: Arc<
|
||||||
|
tokio::sync::Mutex<
|
||||||
|
std::collections::HashMap<
|
||||||
|
uuid::Uuid,
|
||||||
|
std::collections::VecDeque<crate::orchestrator::api::PendingPrompt>,
|
||||||
|
>,
|
||||||
|
>,
|
||||||
|
>,
|
||||||
|
) -> Self {
|
||||||
|
self.rebuild_state(|s| s.prompt_queue = Some(pq));
|
||||||
|
self
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Inject the LLM provider for OpenAI-compatible API proxy.
|
||||||
|
pub fn with_llm_provider(mut self, llm: Arc<dyn crate::llm::LlmProvider>) -> Self {
|
||||||
|
self.rebuild_state(|s| s.llm_provider = Some(llm));
|
||||||
|
self
|
||||||
|
}
|
||||||
|
|
||||||
/// Get the auth token (for printing to console on startup).
|
/// Get the auth token (for printing to console on startup).
|
||||||
pub fn auth_token(&self) -> &str {
|
pub fn auth_token(&self) -> &str {
|
||||||
&self.auth_token
|
&self.auth_token
|
||||||
@@ -173,12 +211,8 @@ impl Channel for GatewayChannel {
|
|||||||
),
|
),
|
||||||
})?;
|
})?;
|
||||||
|
|
||||||
let bound_addr =
|
|
||||||
server::start_server(addr, self.state.clone(), self.auth_token.clone()).await?;
|
server::start_server(addr, self.state.clone(), self.auth_token.clone()).await?;
|
||||||
|
|
||||||
tracing::info!("Web gateway listening on http://{}", bound_addr);
|
|
||||||
tracing::info!("Auth token: {}", self.auth_token);
|
|
||||||
|
|
||||||
Ok(Box::pin(ReceiverStream::new(rx)))
|
Ok(Box::pin(ReceiverStream::new(rx)))
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -200,17 +234,48 @@ impl Channel for GatewayChannel {
|
|||||||
async fn send_status(
|
async fn send_status(
|
||||||
&self,
|
&self,
|
||||||
status: StatusUpdate,
|
status: StatusUpdate,
|
||||||
_metadata: &serde_json::Value,
|
metadata: &serde_json::Value,
|
||||||
) -> Result<(), ChannelError> {
|
) -> Result<(), ChannelError> {
|
||||||
|
let thread_id = metadata
|
||||||
|
.get("thread_id")
|
||||||
|
.and_then(|v| v.as_str())
|
||||||
|
.map(String::from);
|
||||||
let event = match status {
|
let event = match status {
|
||||||
StatusUpdate::Thinking(msg) => SseEvent::Thinking { message: msg },
|
StatusUpdate::Thinking(msg) => SseEvent::Thinking {
|
||||||
StatusUpdate::ToolStarted { name } => SseEvent::ToolStarted { name },
|
message: msg,
|
||||||
StatusUpdate::ToolCompleted { name, success } => {
|
thread_id: thread_id.clone(),
|
||||||
SseEvent::ToolCompleted { name, success }
|
},
|
||||||
}
|
StatusUpdate::ToolStarted { name } => SseEvent::ToolStarted {
|
||||||
StatusUpdate::ToolResult { name, preview } => SseEvent::ToolResult { name, preview },
|
name,
|
||||||
StatusUpdate::StreamChunk(content) => SseEvent::StreamChunk { content },
|
thread_id: thread_id.clone(),
|
||||||
StatusUpdate::Status(msg) => SseEvent::Status { message: msg },
|
},
|
||||||
|
StatusUpdate::ToolCompleted { name, success } => SseEvent::ToolCompleted {
|
||||||
|
name,
|
||||||
|
success,
|
||||||
|
thread_id: thread_id.clone(),
|
||||||
|
},
|
||||||
|
StatusUpdate::ToolResult { name, preview } => SseEvent::ToolResult {
|
||||||
|
name,
|
||||||
|
preview,
|
||||||
|
thread_id: thread_id.clone(),
|
||||||
|
},
|
||||||
|
StatusUpdate::StreamChunk(content) => SseEvent::StreamChunk {
|
||||||
|
content,
|
||||||
|
thread_id: thread_id.clone(),
|
||||||
|
},
|
||||||
|
StatusUpdate::Status(msg) => SseEvent::Status {
|
||||||
|
message: msg,
|
||||||
|
thread_id: thread_id.clone(),
|
||||||
|
},
|
||||||
|
StatusUpdate::JobStarted {
|
||||||
|
job_id,
|
||||||
|
title,
|
||||||
|
browse_url,
|
||||||
|
} => SseEvent::JobStarted {
|
||||||
|
job_id,
|
||||||
|
title,
|
||||||
|
browse_url,
|
||||||
|
},
|
||||||
StatusUpdate::ApprovalNeeded {
|
StatusUpdate::ApprovalNeeded {
|
||||||
request_id,
|
request_id,
|
||||||
tool_name,
|
tool_name,
|
||||||
@@ -223,6 +288,26 @@ impl Channel for GatewayChannel {
|
|||||||
parameters: serde_json::to_string_pretty(¶meters)
|
parameters: serde_json::to_string_pretty(¶meters)
|
||||||
.unwrap_or_else(|_| parameters.to_string()),
|
.unwrap_or_else(|_| parameters.to_string()),
|
||||||
},
|
},
|
||||||
|
StatusUpdate::AuthRequired {
|
||||||
|
extension_name,
|
||||||
|
instructions,
|
||||||
|
auth_url,
|
||||||
|
setup_url,
|
||||||
|
} => SseEvent::AuthRequired {
|
||||||
|
extension_name,
|
||||||
|
instructions,
|
||||||
|
auth_url,
|
||||||
|
setup_url,
|
||||||
|
},
|
||||||
|
StatusUpdate::AuthCompleted {
|
||||||
|
extension_name,
|
||||||
|
success,
|
||||||
|
message,
|
||||||
|
} => SseEvent::AuthCompleted {
|
||||||
|
extension_name,
|
||||||
|
success,
|
||||||
|
message,
|
||||||
|
},
|
||||||
};
|
};
|
||||||
|
|
||||||
self.state.sse.broadcast(event);
|
self.state.sse.broadcast(event);
|
||||||
|
|||||||
File diff suppressed because it is too large
Load Diff
+1529
-78
File diff suppressed because it is too large
Load Diff
+70
-13
@@ -13,10 +13,15 @@ use tokio_stream::wrappers::BroadcastStream;
|
|||||||
|
|
||||||
use crate::channels::web::types::SseEvent;
|
use crate::channels::web::types::SseEvent;
|
||||||
|
|
||||||
|
/// Maximum number of concurrent SSE/WebSocket connections.
|
||||||
|
/// Prevents resource exhaustion from connection flooding.
|
||||||
|
const MAX_CONNECTIONS: u64 = 100;
|
||||||
|
|
||||||
/// Manages SSE broadcast to all connected browser tabs.
|
/// Manages SSE broadcast to all connected browser tabs.
|
||||||
pub struct SseManager {
|
pub struct SseManager {
|
||||||
tx: broadcast::Sender<SseEvent>,
|
tx: broadcast::Sender<SseEvent>,
|
||||||
connection_count: Arc<AtomicU64>,
|
connection_count: Arc<AtomicU64>,
|
||||||
|
max_connections: u64,
|
||||||
}
|
}
|
||||||
|
|
||||||
impl SseManager {
|
impl SseManager {
|
||||||
@@ -27,6 +32,7 @@ impl SseManager {
|
|||||||
Self {
|
Self {
|
||||||
tx,
|
tx,
|
||||||
connection_count: Arc::new(AtomicU64::new(0)),
|
connection_count: Arc::new(AtomicU64::new(0)),
|
||||||
|
max_connections: MAX_CONNECTIONS,
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -45,25 +51,50 @@ impl SseManager {
|
|||||||
///
|
///
|
||||||
/// Returns a stream of `SseEvent` values and increments/decrements the
|
/// Returns a stream of `SseEvent` values and increments/decrements the
|
||||||
/// connection counter on creation/drop, just like `subscribe()` does for SSE.
|
/// connection counter on creation/drop, just like `subscribe()` does for SSE.
|
||||||
pub fn subscribe_raw(&self) -> impl Stream<Item = SseEvent> + Send + 'static + use<> {
|
///
|
||||||
|
/// Returns `None` if the maximum connection limit has been reached.
|
||||||
|
pub fn subscribe_raw(&self) -> Option<impl Stream<Item = SseEvent> + Send + 'static + use<>> {
|
||||||
|
// Atomically increment only if below the limit. This prevents
|
||||||
|
// concurrent callers from overshooting max_connections.
|
||||||
let counter = Arc::clone(&self.connection_count);
|
let counter = Arc::clone(&self.connection_count);
|
||||||
counter.fetch_add(1, Ordering::Relaxed);
|
let max = self.max_connections;
|
||||||
|
counter
|
||||||
|
.fetch_update(Ordering::Relaxed, Ordering::Relaxed, |current| {
|
||||||
|
if current < max {
|
||||||
|
Some(current + 1)
|
||||||
|
} else {
|
||||||
|
None
|
||||||
|
}
|
||||||
|
})
|
||||||
|
.ok()?;
|
||||||
let rx = self.tx.subscribe();
|
let rx = self.tx.subscribe();
|
||||||
|
|
||||||
let stream = BroadcastStream::new(rx).filter_map(|result| result.ok());
|
let stream = BroadcastStream::new(rx).filter_map(|result| result.ok());
|
||||||
|
|
||||||
CountedStream {
|
Some(CountedStream {
|
||||||
inner: stream,
|
inner: stream,
|
||||||
counter,
|
counter,
|
||||||
}
|
})
|
||||||
}
|
}
|
||||||
|
|
||||||
/// Create a new SSE stream for a client connection.
|
/// Create a new SSE stream for a client connection.
|
||||||
|
///
|
||||||
|
/// Returns `None` if the maximum connection limit has been reached.
|
||||||
pub fn subscribe(
|
pub fn subscribe(
|
||||||
&self,
|
&self,
|
||||||
) -> Sse<impl Stream<Item = Result<Event, Infallible>> + Send + 'static + use<>> {
|
) -> Option<Sse<impl Stream<Item = Result<Event, Infallible>> + Send + 'static + use<>>> {
|
||||||
|
// Atomically increment only if below the limit.
|
||||||
let counter = Arc::clone(&self.connection_count);
|
let counter = Arc::clone(&self.connection_count);
|
||||||
counter.fetch_add(1, Ordering::Relaxed);
|
let max = self.max_connections;
|
||||||
|
counter
|
||||||
|
.fetch_update(Ordering::Relaxed, Ordering::Relaxed, |current| {
|
||||||
|
if current < max {
|
||||||
|
Some(current + 1)
|
||||||
|
} else {
|
||||||
|
None
|
||||||
|
}
|
||||||
|
})
|
||||||
|
.ok()?;
|
||||||
let rx = self.tx.subscribe();
|
let rx = self.tx.subscribe();
|
||||||
|
|
||||||
let stream = BroadcastStream::new(rx)
|
let stream = BroadcastStream::new(rx)
|
||||||
@@ -79,7 +110,15 @@ impl SseManager {
|
|||||||
SseEvent::StreamChunk { .. } => "stream_chunk",
|
SseEvent::StreamChunk { .. } => "stream_chunk",
|
||||||
SseEvent::Status { .. } => "status",
|
SseEvent::Status { .. } => "status",
|
||||||
SseEvent::ApprovalNeeded { .. } => "approval_needed",
|
SseEvent::ApprovalNeeded { .. } => "approval_needed",
|
||||||
|
SseEvent::AuthRequired { .. } => "auth_required",
|
||||||
|
SseEvent::AuthCompleted { .. } => "auth_completed",
|
||||||
SseEvent::Error { .. } => "error",
|
SseEvent::Error { .. } => "error",
|
||||||
|
SseEvent::JobStarted { .. } => "job_started",
|
||||||
|
SseEvent::JobMessage { .. } => "job_message",
|
||||||
|
SseEvent::JobToolUse { .. } => "job_tool_use",
|
||||||
|
SseEvent::JobToolResult { .. } => "job_tool_result",
|
||||||
|
SseEvent::JobStatus { .. } => "job_status",
|
||||||
|
SseEvent::JobResult { .. } => "job_result",
|
||||||
SseEvent::Heartbeat => "heartbeat",
|
SseEvent::Heartbeat => "heartbeat",
|
||||||
};
|
};
|
||||||
Ok(Event::default().event(event_type).data(data))
|
Ok(Event::default().event(event_type).data(data))
|
||||||
@@ -91,8 +130,10 @@ impl SseManager {
|
|||||||
counter,
|
counter,
|
||||||
};
|
};
|
||||||
|
|
||||||
|
Some(
|
||||||
Sse::new(counted_stream)
|
Sse::new(counted_stream)
|
||||||
.keep_alive(KeepAlive::new().interval(Duration::from_secs(30)).text(""))
|
.keep_alive(KeepAlive::new().interval(Duration::from_secs(30)).text("")),
|
||||||
|
)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -152,13 +193,14 @@ mod tests {
|
|||||||
|
|
||||||
manager.broadcast(SseEvent::Status {
|
manager.broadcast(SseEvent::Status {
|
||||||
message: "test".to_string(),
|
message: "test".to_string(),
|
||||||
|
thread_id: None,
|
||||||
});
|
});
|
||||||
|
|
||||||
let event = rx.next().await;
|
let event = rx.next().await;
|
||||||
assert!(event.is_some());
|
assert!(event.is_some());
|
||||||
let event = event.unwrap().unwrap();
|
let event = event.unwrap().unwrap();
|
||||||
match event {
|
match event {
|
||||||
SseEvent::Status { message } => assert_eq!(message, "test"),
|
SseEvent::Status { message, .. } => assert_eq!(message, "test"),
|
||||||
_ => panic!("unexpected event type"),
|
_ => panic!("unexpected event type"),
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -166,17 +208,18 @@ mod tests {
|
|||||||
#[tokio::test]
|
#[tokio::test]
|
||||||
async fn test_subscribe_raw_receives_events() {
|
async fn test_subscribe_raw_receives_events() {
|
||||||
let manager = SseManager::new();
|
let manager = SseManager::new();
|
||||||
let mut stream = Box::pin(manager.subscribe_raw());
|
let mut stream = Box::pin(manager.subscribe_raw().expect("should subscribe"));
|
||||||
|
|
||||||
assert_eq!(manager.connection_count(), 1);
|
assert_eq!(manager.connection_count(), 1);
|
||||||
|
|
||||||
manager.broadcast(SseEvent::Thinking {
|
manager.broadcast(SseEvent::Thinking {
|
||||||
message: "working".to_string(),
|
message: "working".to_string(),
|
||||||
|
thread_id: None,
|
||||||
});
|
});
|
||||||
|
|
||||||
let event = stream.next().await.unwrap();
|
let event = stream.next().await.unwrap();
|
||||||
match event {
|
match event {
|
||||||
SseEvent::Thinking { message } => assert_eq!(message, "working"),
|
SseEvent::Thinking { message, .. } => assert_eq!(message, "working"),
|
||||||
_ => panic!("Expected Thinking event"),
|
_ => panic!("Expected Thinking event"),
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -185,7 +228,7 @@ mod tests {
|
|||||||
async fn test_subscribe_raw_decrements_on_drop() {
|
async fn test_subscribe_raw_decrements_on_drop() {
|
||||||
let manager = SseManager::new();
|
let manager = SseManager::new();
|
||||||
{
|
{
|
||||||
let _stream = Box::pin(manager.subscribe_raw());
|
let _stream = Box::pin(manager.subscribe_raw().expect("should subscribe"));
|
||||||
assert_eq!(manager.connection_count(), 1);
|
assert_eq!(manager.connection_count(), 1);
|
||||||
}
|
}
|
||||||
// Stream dropped, counter should decrement
|
// Stream dropped, counter should decrement
|
||||||
@@ -195,8 +238,8 @@ mod tests {
|
|||||||
#[tokio::test]
|
#[tokio::test]
|
||||||
async fn test_subscribe_raw_multiple_subscribers() {
|
async fn test_subscribe_raw_multiple_subscribers() {
|
||||||
let manager = SseManager::new();
|
let manager = SseManager::new();
|
||||||
let mut s1 = Box::pin(manager.subscribe_raw());
|
let mut s1 = Box::pin(manager.subscribe_raw().expect("should subscribe"));
|
||||||
let mut s2 = Box::pin(manager.subscribe_raw());
|
let mut s2 = Box::pin(manager.subscribe_raw().expect("should subscribe"));
|
||||||
assert_eq!(manager.connection_count(), 2);
|
assert_eq!(manager.connection_count(), 2);
|
||||||
|
|
||||||
manager.broadcast(SseEvent::Heartbeat);
|
manager.broadcast(SseEvent::Heartbeat);
|
||||||
@@ -211,4 +254,18 @@ mod tests {
|
|||||||
drop(s2);
|
drop(s2);
|
||||||
assert_eq!(manager.connection_count(), 0);
|
assert_eq!(manager.connection_count(), 0);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
#[tokio::test]
|
||||||
|
async fn test_subscribe_raw_rejects_over_limit() {
|
||||||
|
let mut manager = SseManager::new();
|
||||||
|
manager.max_connections = 2; // Low limit for testing
|
||||||
|
|
||||||
|
let _s1 = Box::pin(manager.subscribe_raw().expect("first should succeed"));
|
||||||
|
let _s2 = Box::pin(manager.subscribe_raw().expect("second should succeed"));
|
||||||
|
assert_eq!(manager.connection_count(), 2);
|
||||||
|
|
||||||
|
// Third should be rejected
|
||||||
|
assert!(manager.subscribe_raw().is_none());
|
||||||
|
assert!(manager.subscribe().is_none());
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
+1373
-30
File diff suppressed because it is too large
Load Diff
@@ -10,12 +10,19 @@
|
|||||||
<body>
|
<body>
|
||||||
<!-- Auth Screen -->
|
<!-- Auth Screen -->
|
||||||
<div id="auth-screen">
|
<div id="auth-screen">
|
||||||
|
<div class="auth-card-login">
|
||||||
|
<div class="auth-brand">
|
||||||
<h1>IronClaw</h1>
|
<h1>IronClaw</h1>
|
||||||
|
<p class="auth-tagline">Secure AI Assistant</p>
|
||||||
|
</div>
|
||||||
<div class="auth-form">
|
<div class="auth-form">
|
||||||
<input type="password" id="token-input" placeholder="Auth token" autofocus>
|
<label for="token-input">Gateway Token</label>
|
||||||
|
<input type="password" id="token-input" placeholder="Paste your auth token" autofocus>
|
||||||
<button onclick="authenticate()">Connect</button>
|
<button onclick="authenticate()">Connect</button>
|
||||||
</div>
|
</div>
|
||||||
<div id="auth-error"></div>
|
<div id="auth-error"></div>
|
||||||
|
<p class="auth-hint">Enter the GATEWAY_AUTH_TOKEN from your .env configuration.</p>
|
||||||
|
</div>
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
<!-- Main App (hidden until authenticated) -->
|
<!-- Main App (hidden until authenticated) -->
|
||||||
@@ -26,16 +33,33 @@
|
|||||||
<button data-tab="memory">Memory</button>
|
<button data-tab="memory">Memory</button>
|
||||||
<button data-tab="jobs">Jobs</button>
|
<button data-tab="jobs">Jobs</button>
|
||||||
<button data-tab="logs">Logs</button>
|
<button data-tab="logs">Logs</button>
|
||||||
|
<button data-tab="routines">Routines</button>
|
||||||
<button data-tab="extensions">Extensions</button>
|
<button data-tab="extensions">Extensions</button>
|
||||||
<div class="spacer"></div>
|
<div class="spacer"></div>
|
||||||
<div class="status">
|
<div class="status" id="gateway-status-trigger">
|
||||||
<div class="dot" id="sse-dot"></div>
|
<div class="dot" id="sse-dot"></div>
|
||||||
<span id="sse-status">Connected</span>
|
<span id="sse-status">Connected</span>
|
||||||
|
<div class="gateway-popover" id="gateway-popover"></div>
|
||||||
</div>
|
</div>
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
<!-- Chat Tab -->
|
<!-- Chat Tab -->
|
||||||
<div class="tab-panel active" id="tab-chat">
|
<div class="tab-panel active" id="tab-chat">
|
||||||
|
<div class="thread-sidebar" id="thread-sidebar">
|
||||||
|
<div class="thread-sidebar-header">
|
||||||
|
<span>Threads</span>
|
||||||
|
<button class="thread-new-btn" onclick="createNewThread()" title="New thread (Ctrl/Cmd+N)">+</button>
|
||||||
|
<button class="thread-toggle-btn" id="thread-toggle-btn" onclick="toggleThreadSidebar()" title="Toggle sidebar">«</button>
|
||||||
|
</div>
|
||||||
|
<div class="assistant-item" id="assistant-thread" onclick="switchToAssistant()">
|
||||||
|
<span class="assistant-label">Assistant</span>
|
||||||
|
<span class="assistant-meta" id="assistant-meta"></span>
|
||||||
|
</div>
|
||||||
|
<div class="threads-section-header">
|
||||||
|
<span>Conversations</span>
|
||||||
|
</div>
|
||||||
|
<div class="thread-list" id="thread-list"></div>
|
||||||
|
</div>
|
||||||
<div class="chat-container">
|
<div class="chat-container">
|
||||||
<div class="chat-messages" id="chat-messages"></div>
|
<div class="chat-messages" id="chat-messages"></div>
|
||||||
<div class="chat-status" id="chat-status"></div>
|
<div class="chat-status" id="chat-status"></div>
|
||||||
@@ -56,10 +80,20 @@
|
|||||||
<div class="memory-tree" id="memory-tree"></div>
|
<div class="memory-tree" id="memory-tree"></div>
|
||||||
</div>
|
</div>
|
||||||
<div class="memory-content">
|
<div class="memory-content">
|
||||||
<div class="memory-breadcrumb" id="memory-breadcrumb">workspace /</div>
|
<div class="memory-breadcrumb" id="memory-breadcrumb">
|
||||||
|
<span id="memory-breadcrumb-path">workspace /</span>
|
||||||
|
<button class="memory-edit-btn" id="memory-edit-btn" style="display:none" onclick="startMemoryEdit()">Edit</button>
|
||||||
|
</div>
|
||||||
<div class="memory-viewer" id="memory-viewer">
|
<div class="memory-viewer" id="memory-viewer">
|
||||||
<div class="empty">Select a file to view its contents</div>
|
<div class="empty">Select a file to view its contents</div>
|
||||||
</div>
|
</div>
|
||||||
|
<div class="memory-editor" id="memory-editor" style="display:none">
|
||||||
|
<textarea id="memory-edit-textarea"></textarea>
|
||||||
|
<div class="memory-editor-actions">
|
||||||
|
<button class="btn-save" onclick="saveMemoryEdit()">Save</button>
|
||||||
|
<button class="btn-cancel-edit" onclick="cancelMemoryEdit()">Cancel</button>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
</div>
|
</div>
|
||||||
</div>
|
</div>
|
||||||
</div>
|
</div>
|
||||||
@@ -73,6 +107,7 @@
|
|||||||
<tr>
|
<tr>
|
||||||
<th>ID</th>
|
<th>ID</th>
|
||||||
<th>Title</th>
|
<th>Title</th>
|
||||||
|
<th>Source</th>
|
||||||
<th>Status</th>
|
<th>Status</th>
|
||||||
<th>Created</th>
|
<th>Created</th>
|
||||||
<th>Actions</th>
|
<th>Actions</th>
|
||||||
@@ -104,9 +139,48 @@
|
|||||||
</div>
|
</div>
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
|
<!-- Routines Tab -->
|
||||||
|
<div class="tab-panel" id="tab-routines">
|
||||||
|
<div class="routines-container">
|
||||||
|
<div class="routines-summary" id="routines-summary"></div>
|
||||||
|
<table class="routines-table" id="routines-table">
|
||||||
|
<thead>
|
||||||
|
<tr>
|
||||||
|
<th>Name</th>
|
||||||
|
<th>Trigger</th>
|
||||||
|
<th>Action</th>
|
||||||
|
<th>Last Run</th>
|
||||||
|
<th>Next Run</th>
|
||||||
|
<th>Runs</th>
|
||||||
|
<th>Status</th>
|
||||||
|
<th>Actions</th>
|
||||||
|
</tr>
|
||||||
|
</thead>
|
||||||
|
<tbody id="routines-tbody"></tbody>
|
||||||
|
</table>
|
||||||
|
<div class="empty-state" id="routines-empty" style="display:none">
|
||||||
|
No routines configured. Ask the assistant to create one.
|
||||||
|
</div>
|
||||||
|
<div class="routine-detail" id="routine-detail" style="display:none"></div>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
|
||||||
<!-- Extensions Tab -->
|
<!-- Extensions Tab -->
|
||||||
<div class="tab-panel" id="tab-extensions">
|
<div class="tab-panel" id="tab-extensions">
|
||||||
<div class="extensions-container">
|
<div class="extensions-container">
|
||||||
|
<div class="extensions-section">
|
||||||
|
<h3>Install Extension</h3>
|
||||||
|
<div class="ext-install-form" id="ext-install-form">
|
||||||
|
<input type="text" id="ext-install-name" placeholder="Extension name (required)">
|
||||||
|
<input type="text" id="ext-install-url" placeholder="URL (optional)">
|
||||||
|
<select id="ext-install-kind">
|
||||||
|
<option value="mcp_server">MCP Server</option>
|
||||||
|
<option value="wasm_tool">WASM Tool</option>
|
||||||
|
<option value="wasm_channel">WASM Channel</option>
|
||||||
|
</select>
|
||||||
|
<button onclick="installExtension()">Install</button>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
<div class="extensions-section">
|
<div class="extensions-section">
|
||||||
<h3>Installed Extensions</h3>
|
<h3>Installed Extensions</h3>
|
||||||
<div class="extensions-list" id="extensions-list">
|
<div class="extensions-list" id="extensions-list">
|
||||||
@@ -130,6 +204,7 @@
|
|||||||
</div>
|
</div>
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
|
<div id="toasts"></div>
|
||||||
<script src="/app.js"></script>
|
<script src="/app.js"></script>
|
||||||
</body>
|
</body>
|
||||||
</html>
|
</html>
|
||||||
|
|||||||
File diff suppressed because it is too large
Load Diff
+414
-9
@@ -24,10 +24,17 @@ pub struct ThreadInfo {
|
|||||||
pub turn_count: usize,
|
pub turn_count: usize,
|
||||||
pub created_at: String,
|
pub created_at: String,
|
||||||
pub updated_at: String,
|
pub updated_at: String,
|
||||||
|
#[serde(skip_serializing_if = "Option::is_none")]
|
||||||
|
pub title: Option<String>,
|
||||||
|
#[serde(skip_serializing_if = "Option::is_none")]
|
||||||
|
pub thread_type: Option<String>,
|
||||||
}
|
}
|
||||||
|
|
||||||
#[derive(Debug, Serialize)]
|
#[derive(Debug, Serialize)]
|
||||||
pub struct ThreadListResponse {
|
pub struct ThreadListResponse {
|
||||||
|
/// The pinned assistant thread (always present after first load).
|
||||||
|
pub assistant_thread: Option<ThreadInfo>,
|
||||||
|
/// Regular conversation threads.
|
||||||
pub threads: Vec<ThreadInfo>,
|
pub threads: Vec<ThreadInfo>,
|
||||||
pub active_thread: Option<Uuid>,
|
pub active_thread: Option<Uuid>,
|
||||||
}
|
}
|
||||||
@@ -54,6 +61,12 @@ pub struct ToolCallInfo {
|
|||||||
pub struct HistoryResponse {
|
pub struct HistoryResponse {
|
||||||
pub thread_id: Uuid,
|
pub thread_id: Uuid,
|
||||||
pub turns: Vec<TurnInfo>,
|
pub turns: Vec<TurnInfo>,
|
||||||
|
/// Whether there are older messages available.
|
||||||
|
#[serde(default)]
|
||||||
|
pub has_more: bool,
|
||||||
|
/// Cursor for the next page (ISO8601 timestamp of the oldest message returned).
|
||||||
|
#[serde(skip_serializing_if = "Option::is_none")]
|
||||||
|
pub oldest_timestamp: Option<String>,
|
||||||
}
|
}
|
||||||
|
|
||||||
// --- Approval ---
|
// --- Approval ---
|
||||||
@@ -63,6 +76,8 @@ pub struct ApprovalRequest {
|
|||||||
pub request_id: String,
|
pub request_id: String,
|
||||||
/// "approve", "always", or "deny"
|
/// "approve", "always", or "deny"
|
||||||
pub action: String,
|
pub action: String,
|
||||||
|
/// Thread that owns the pending approval (so the agent loop finds the right session).
|
||||||
|
pub thread_id: Option<String>,
|
||||||
}
|
}
|
||||||
|
|
||||||
// --- SSE Event Types ---
|
// --- SSE Event Types ---
|
||||||
@@ -73,17 +88,49 @@ pub enum SseEvent {
|
|||||||
#[serde(rename = "response")]
|
#[serde(rename = "response")]
|
||||||
Response { content: String, thread_id: String },
|
Response { content: String, thread_id: String },
|
||||||
#[serde(rename = "thinking")]
|
#[serde(rename = "thinking")]
|
||||||
Thinking { message: String },
|
Thinking {
|
||||||
|
message: String,
|
||||||
|
#[serde(skip_serializing_if = "Option::is_none")]
|
||||||
|
thread_id: Option<String>,
|
||||||
|
},
|
||||||
#[serde(rename = "tool_started")]
|
#[serde(rename = "tool_started")]
|
||||||
ToolStarted { name: String },
|
ToolStarted {
|
||||||
|
name: String,
|
||||||
|
#[serde(skip_serializing_if = "Option::is_none")]
|
||||||
|
thread_id: Option<String>,
|
||||||
|
},
|
||||||
#[serde(rename = "tool_completed")]
|
#[serde(rename = "tool_completed")]
|
||||||
ToolCompleted { name: String, success: bool },
|
ToolCompleted {
|
||||||
|
name: String,
|
||||||
|
success: bool,
|
||||||
|
#[serde(skip_serializing_if = "Option::is_none")]
|
||||||
|
thread_id: Option<String>,
|
||||||
|
},
|
||||||
#[serde(rename = "tool_result")]
|
#[serde(rename = "tool_result")]
|
||||||
ToolResult { name: String, preview: String },
|
ToolResult {
|
||||||
|
name: String,
|
||||||
|
preview: String,
|
||||||
|
#[serde(skip_serializing_if = "Option::is_none")]
|
||||||
|
thread_id: Option<String>,
|
||||||
|
},
|
||||||
#[serde(rename = "stream_chunk")]
|
#[serde(rename = "stream_chunk")]
|
||||||
StreamChunk { content: String },
|
StreamChunk {
|
||||||
|
content: String,
|
||||||
|
#[serde(skip_serializing_if = "Option::is_none")]
|
||||||
|
thread_id: Option<String>,
|
||||||
|
},
|
||||||
#[serde(rename = "status")]
|
#[serde(rename = "status")]
|
||||||
Status { message: String },
|
Status {
|
||||||
|
message: String,
|
||||||
|
#[serde(skip_serializing_if = "Option::is_none")]
|
||||||
|
thread_id: Option<String>,
|
||||||
|
},
|
||||||
|
#[serde(rename = "job_started")]
|
||||||
|
JobStarted {
|
||||||
|
job_id: String,
|
||||||
|
title: String,
|
||||||
|
browse_url: String,
|
||||||
|
},
|
||||||
#[serde(rename = "approval_needed")]
|
#[serde(rename = "approval_needed")]
|
||||||
ApprovalNeeded {
|
ApprovalNeeded {
|
||||||
request_id: String,
|
request_id: String,
|
||||||
@@ -91,10 +138,59 @@ pub enum SseEvent {
|
|||||||
description: String,
|
description: String,
|
||||||
parameters: String,
|
parameters: String,
|
||||||
},
|
},
|
||||||
|
#[serde(rename = "auth_required")]
|
||||||
|
AuthRequired {
|
||||||
|
extension_name: String,
|
||||||
|
#[serde(skip_serializing_if = "Option::is_none")]
|
||||||
|
instructions: Option<String>,
|
||||||
|
#[serde(skip_serializing_if = "Option::is_none")]
|
||||||
|
auth_url: Option<String>,
|
||||||
|
#[serde(skip_serializing_if = "Option::is_none")]
|
||||||
|
setup_url: Option<String>,
|
||||||
|
},
|
||||||
|
#[serde(rename = "auth_completed")]
|
||||||
|
AuthCompleted {
|
||||||
|
extension_name: String,
|
||||||
|
success: bool,
|
||||||
|
message: String,
|
||||||
|
},
|
||||||
#[serde(rename = "error")]
|
#[serde(rename = "error")]
|
||||||
Error { message: String },
|
Error {
|
||||||
|
message: String,
|
||||||
|
#[serde(skip_serializing_if = "Option::is_none")]
|
||||||
|
thread_id: Option<String>,
|
||||||
|
},
|
||||||
#[serde(rename = "heartbeat")]
|
#[serde(rename = "heartbeat")]
|
||||||
Heartbeat,
|
Heartbeat,
|
||||||
|
|
||||||
|
// Sandbox job streaming events (worker + Claude Code bridge)
|
||||||
|
#[serde(rename = "job_message")]
|
||||||
|
JobMessage {
|
||||||
|
job_id: String,
|
||||||
|
role: String,
|
||||||
|
content: String,
|
||||||
|
},
|
||||||
|
#[serde(rename = "job_tool_use")]
|
||||||
|
JobToolUse {
|
||||||
|
job_id: String,
|
||||||
|
tool_name: String,
|
||||||
|
input: serde_json::Value,
|
||||||
|
},
|
||||||
|
#[serde(rename = "job_tool_result")]
|
||||||
|
JobToolResult {
|
||||||
|
job_id: String,
|
||||||
|
tool_name: String,
|
||||||
|
output: String,
|
||||||
|
},
|
||||||
|
#[serde(rename = "job_status")]
|
||||||
|
JobStatus { job_id: String, message: String },
|
||||||
|
#[serde(rename = "job_result")]
|
||||||
|
JobResult {
|
||||||
|
job_id: String,
|
||||||
|
status: String,
|
||||||
|
#[serde(skip_serializing_if = "Option::is_none")]
|
||||||
|
session_id: Option<String>,
|
||||||
|
},
|
||||||
}
|
}
|
||||||
|
|
||||||
// --- Memory ---
|
// --- Memory ---
|
||||||
@@ -188,6 +284,54 @@ pub struct JobSummaryResponse {
|
|||||||
pub stuck: usize,
|
pub stuck: usize,
|
||||||
}
|
}
|
||||||
|
|
||||||
|
#[derive(Debug, Serialize)]
|
||||||
|
pub struct JobDetailResponse {
|
||||||
|
pub id: Uuid,
|
||||||
|
pub title: String,
|
||||||
|
pub description: String,
|
||||||
|
pub state: String,
|
||||||
|
pub user_id: String,
|
||||||
|
pub created_at: String,
|
||||||
|
pub started_at: Option<String>,
|
||||||
|
pub completed_at: Option<String>,
|
||||||
|
pub elapsed_secs: Option<u64>,
|
||||||
|
#[serde(skip_serializing_if = "Option::is_none")]
|
||||||
|
pub project_dir: Option<String>,
|
||||||
|
#[serde(skip_serializing_if = "Option::is_none")]
|
||||||
|
pub browse_url: Option<String>,
|
||||||
|
#[serde(skip_serializing_if = "Option::is_none")]
|
||||||
|
pub job_mode: Option<String>,
|
||||||
|
pub transitions: Vec<TransitionInfo>,
|
||||||
|
}
|
||||||
|
|
||||||
|
// --- Project Files ---
|
||||||
|
|
||||||
|
#[derive(Debug, Serialize)]
|
||||||
|
pub struct ProjectFileEntry {
|
||||||
|
pub name: String,
|
||||||
|
pub path: String,
|
||||||
|
pub is_dir: bool,
|
||||||
|
}
|
||||||
|
|
||||||
|
#[derive(Debug, Serialize)]
|
||||||
|
pub struct ProjectFilesResponse {
|
||||||
|
pub entries: Vec<ProjectFileEntry>,
|
||||||
|
}
|
||||||
|
|
||||||
|
#[derive(Debug, Serialize)]
|
||||||
|
pub struct ProjectFileReadResponse {
|
||||||
|
pub path: String,
|
||||||
|
pub content: String,
|
||||||
|
}
|
||||||
|
|
||||||
|
#[derive(Debug, Serialize)]
|
||||||
|
pub struct TransitionInfo {
|
||||||
|
pub from: String,
|
||||||
|
pub to: String,
|
||||||
|
pub timestamp: String,
|
||||||
|
pub reason: Option<String>,
|
||||||
|
}
|
||||||
|
|
||||||
// --- Extensions ---
|
// --- Extensions ---
|
||||||
|
|
||||||
#[derive(Debug, Serialize)]
|
#[derive(Debug, Serialize)]
|
||||||
@@ -262,6 +406,21 @@ impl ActionResponse {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// --- Auth Token ---
|
||||||
|
|
||||||
|
/// Request to submit an auth token for an extension (dedicated endpoint).
|
||||||
|
#[derive(Debug, Deserialize)]
|
||||||
|
pub struct AuthTokenRequest {
|
||||||
|
pub extension_name: String,
|
||||||
|
pub token: String,
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Request to cancel an in-progress auth flow.
|
||||||
|
#[derive(Debug, Deserialize)]
|
||||||
|
pub struct AuthCancelRequest {
|
||||||
|
pub extension_name: String,
|
||||||
|
}
|
||||||
|
|
||||||
// --- WebSocket ---
|
// --- WebSocket ---
|
||||||
|
|
||||||
/// Message sent by a WebSocket client to the server.
|
/// Message sent by a WebSocket client to the server.
|
||||||
@@ -280,7 +439,18 @@ pub enum WsClientMessage {
|
|||||||
request_id: String,
|
request_id: String,
|
||||||
/// "approve", "always", or "deny"
|
/// "approve", "always", or "deny"
|
||||||
action: String,
|
action: String,
|
||||||
|
/// Thread that owns the pending approval.
|
||||||
|
thread_id: Option<String>,
|
||||||
},
|
},
|
||||||
|
/// Submit an auth token for an extension (bypasses message pipeline).
|
||||||
|
#[serde(rename = "auth_token")]
|
||||||
|
AuthToken {
|
||||||
|
extension_name: String,
|
||||||
|
token: String,
|
||||||
|
},
|
||||||
|
/// Cancel an in-progress auth flow.
|
||||||
|
#[serde(rename = "auth_cancel")]
|
||||||
|
AuthCancel { extension_name: String },
|
||||||
/// Client heartbeat ping.
|
/// Client heartbeat ping.
|
||||||
#[serde(rename = "ping")]
|
#[serde(rename = "ping")]
|
||||||
Ping,
|
Ping,
|
||||||
@@ -314,11 +484,20 @@ impl WsServerMessage {
|
|||||||
SseEvent::Thinking { .. } => "thinking",
|
SseEvent::Thinking { .. } => "thinking",
|
||||||
SseEvent::ToolStarted { .. } => "tool_started",
|
SseEvent::ToolStarted { .. } => "tool_started",
|
||||||
SseEvent::ToolCompleted { .. } => "tool_completed",
|
SseEvent::ToolCompleted { .. } => "tool_completed",
|
||||||
|
SseEvent::ToolResult { .. } => "tool_result",
|
||||||
SseEvent::StreamChunk { .. } => "stream_chunk",
|
SseEvent::StreamChunk { .. } => "stream_chunk",
|
||||||
SseEvent::Status { .. } => "status",
|
SseEvent::Status { .. } => "status",
|
||||||
|
SseEvent::JobStarted { .. } => "job_started",
|
||||||
SseEvent::ApprovalNeeded { .. } => "approval_needed",
|
SseEvent::ApprovalNeeded { .. } => "approval_needed",
|
||||||
|
SseEvent::AuthRequired { .. } => "auth_required",
|
||||||
|
SseEvent::AuthCompleted { .. } => "auth_completed",
|
||||||
SseEvent::Error { .. } => "error",
|
SseEvent::Error { .. } => "error",
|
||||||
SseEvent::Heartbeat => "heartbeat",
|
SseEvent::Heartbeat => "heartbeat",
|
||||||
|
SseEvent::JobMessage { .. } => "job_message",
|
||||||
|
SseEvent::JobToolUse { .. } => "job_tool_use",
|
||||||
|
SseEvent::JobToolResult { .. } => "job_tool_result",
|
||||||
|
SseEvent::JobStatus { .. } => "job_status",
|
||||||
|
SseEvent::JobResult { .. } => "job_result",
|
||||||
};
|
};
|
||||||
let data = serde_json::to_value(event).unwrap_or(serde_json::Value::Null);
|
let data = serde_json::to_value(event).unwrap_or(serde_json::Value::Null);
|
||||||
WsServerMessage::Event {
|
WsServerMessage::Event {
|
||||||
@@ -328,6 +507,96 @@ impl WsServerMessage {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// --- Routines ---
|
||||||
|
|
||||||
|
#[derive(Debug, Serialize)]
|
||||||
|
pub struct RoutineInfo {
|
||||||
|
pub id: Uuid,
|
||||||
|
pub name: String,
|
||||||
|
pub description: String,
|
||||||
|
pub enabled: bool,
|
||||||
|
pub trigger_type: String,
|
||||||
|
pub trigger_summary: String,
|
||||||
|
pub action_type: String,
|
||||||
|
pub last_run_at: Option<String>,
|
||||||
|
pub next_fire_at: Option<String>,
|
||||||
|
pub run_count: u64,
|
||||||
|
pub consecutive_failures: u32,
|
||||||
|
pub status: String,
|
||||||
|
}
|
||||||
|
|
||||||
|
#[derive(Debug, Serialize)]
|
||||||
|
pub struct RoutineListResponse {
|
||||||
|
pub routines: Vec<RoutineInfo>,
|
||||||
|
}
|
||||||
|
|
||||||
|
#[derive(Debug, Serialize)]
|
||||||
|
pub struct RoutineSummaryResponse {
|
||||||
|
pub total: u64,
|
||||||
|
pub enabled: u64,
|
||||||
|
pub disabled: u64,
|
||||||
|
pub failing: u64,
|
||||||
|
pub runs_today: u64,
|
||||||
|
}
|
||||||
|
|
||||||
|
#[derive(Debug, Serialize)]
|
||||||
|
pub struct RoutineDetailResponse {
|
||||||
|
pub id: Uuid,
|
||||||
|
pub name: String,
|
||||||
|
pub description: String,
|
||||||
|
pub enabled: bool,
|
||||||
|
pub trigger: serde_json::Value,
|
||||||
|
pub action: serde_json::Value,
|
||||||
|
pub guardrails: serde_json::Value,
|
||||||
|
pub notify: serde_json::Value,
|
||||||
|
pub last_run_at: Option<String>,
|
||||||
|
pub next_fire_at: Option<String>,
|
||||||
|
pub run_count: u64,
|
||||||
|
pub consecutive_failures: u32,
|
||||||
|
pub created_at: String,
|
||||||
|
pub recent_runs: Vec<RoutineRunInfo>,
|
||||||
|
}
|
||||||
|
|
||||||
|
#[derive(Debug, Serialize)]
|
||||||
|
pub struct RoutineRunInfo {
|
||||||
|
pub id: Uuid,
|
||||||
|
pub trigger_type: String,
|
||||||
|
pub started_at: String,
|
||||||
|
pub completed_at: Option<String>,
|
||||||
|
pub status: String,
|
||||||
|
pub result_summary: Option<String>,
|
||||||
|
pub tokens_used: Option<i32>,
|
||||||
|
}
|
||||||
|
|
||||||
|
// --- Settings ---
|
||||||
|
|
||||||
|
#[derive(Debug, Serialize)]
|
||||||
|
pub struct SettingResponse {
|
||||||
|
pub key: String,
|
||||||
|
pub value: serde_json::Value,
|
||||||
|
pub updated_at: String,
|
||||||
|
}
|
||||||
|
|
||||||
|
#[derive(Debug, Serialize)]
|
||||||
|
pub struct SettingsListResponse {
|
||||||
|
pub settings: Vec<SettingResponse>,
|
||||||
|
}
|
||||||
|
|
||||||
|
#[derive(Debug, Deserialize)]
|
||||||
|
pub struct SettingWriteRequest {
|
||||||
|
pub value: serde_json::Value,
|
||||||
|
}
|
||||||
|
|
||||||
|
#[derive(Debug, Deserialize)]
|
||||||
|
pub struct SettingsImportRequest {
|
||||||
|
pub settings: std::collections::HashMap<String, serde_json::Value>,
|
||||||
|
}
|
||||||
|
|
||||||
|
#[derive(Debug, Serialize)]
|
||||||
|
pub struct SettingsExportResponse {
|
||||||
|
pub settings: std::collections::HashMap<String, serde_json::Value>,
|
||||||
|
}
|
||||||
|
|
||||||
// --- Health ---
|
// --- Health ---
|
||||||
|
|
||||||
#[derive(Debug, Serialize)]
|
#[derive(Debug, Serialize)]
|
||||||
@@ -370,12 +639,36 @@ mod tests {
|
|||||||
|
|
||||||
#[test]
|
#[test]
|
||||||
fn test_ws_client_approval_parse() {
|
fn test_ws_client_approval_parse() {
|
||||||
let json = r#"{"type":"approval","request_id":"abc-123","action":"approve"}"#;
|
let json =
|
||||||
|
r#"{"type":"approval","request_id":"abc-123","action":"approve","thread_id":"t1"}"#;
|
||||||
let msg: WsClientMessage = serde_json::from_str(json).unwrap();
|
let msg: WsClientMessage = serde_json::from_str(json).unwrap();
|
||||||
match msg {
|
match msg {
|
||||||
WsClientMessage::Approval { request_id, action } => {
|
WsClientMessage::Approval {
|
||||||
|
request_id,
|
||||||
|
action,
|
||||||
|
thread_id,
|
||||||
|
} => {
|
||||||
assert_eq!(request_id, "abc-123");
|
assert_eq!(request_id, "abc-123");
|
||||||
assert_eq!(action, "approve");
|
assert_eq!(action, "approve");
|
||||||
|
assert_eq!(thread_id.as_deref(), Some("t1"));
|
||||||
|
}
|
||||||
|
_ => panic!("Expected Approval variant"),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_ws_client_approval_parse_no_thread() {
|
||||||
|
let json = r#"{"type":"approval","request_id":"abc-123","action":"deny"}"#;
|
||||||
|
let msg: WsClientMessage = serde_json::from_str(json).unwrap();
|
||||||
|
match msg {
|
||||||
|
WsClientMessage::Approval {
|
||||||
|
request_id,
|
||||||
|
action,
|
||||||
|
thread_id,
|
||||||
|
} => {
|
||||||
|
assert_eq!(request_id, "abc-123");
|
||||||
|
assert_eq!(action, "deny");
|
||||||
|
assert!(thread_id.is_none());
|
||||||
}
|
}
|
||||||
_ => panic!("Expected Approval variant"),
|
_ => panic!("Expected Approval variant"),
|
||||||
}
|
}
|
||||||
@@ -436,6 +729,7 @@ mod tests {
|
|||||||
fn test_ws_server_from_sse_thinking() {
|
fn test_ws_server_from_sse_thinking() {
|
||||||
let sse = SseEvent::Thinking {
|
let sse = SseEvent::Thinking {
|
||||||
message: "reasoning...".to_string(),
|
message: "reasoning...".to_string(),
|
||||||
|
thread_id: None,
|
||||||
};
|
};
|
||||||
let ws = WsServerMessage::from_sse_event(&sse);
|
let ws = WsServerMessage::from_sse_event(&sse);
|
||||||
match ws {
|
match ws {
|
||||||
@@ -476,4 +770,115 @@ mod tests {
|
|||||||
_ => panic!("Expected Event variant"),
|
_ => panic!("Expected Event variant"),
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// ---- Auth type tests ----
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_ws_client_auth_token_parse() {
|
||||||
|
let json = r#"{"type":"auth_token","extension_name":"notion","token":"sk-123"}"#;
|
||||||
|
let msg: WsClientMessage = serde_json::from_str(json).unwrap();
|
||||||
|
match msg {
|
||||||
|
WsClientMessage::AuthToken {
|
||||||
|
extension_name,
|
||||||
|
token,
|
||||||
|
} => {
|
||||||
|
assert_eq!(extension_name, "notion");
|
||||||
|
assert_eq!(token, "sk-123");
|
||||||
|
}
|
||||||
|
_ => panic!("Expected AuthToken variant"),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_ws_client_auth_cancel_parse() {
|
||||||
|
let json = r#"{"type":"auth_cancel","extension_name":"notion"}"#;
|
||||||
|
let msg: WsClientMessage = serde_json::from_str(json).unwrap();
|
||||||
|
match msg {
|
||||||
|
WsClientMessage::AuthCancel { extension_name } => {
|
||||||
|
assert_eq!(extension_name, "notion");
|
||||||
|
}
|
||||||
|
_ => panic!("Expected AuthCancel variant"),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_sse_auth_required_serialize() {
|
||||||
|
let event = SseEvent::AuthRequired {
|
||||||
|
extension_name: "notion".to_string(),
|
||||||
|
instructions: Some("Get your token from...".to_string()),
|
||||||
|
auth_url: None,
|
||||||
|
setup_url: Some("https://notion.so/integrations".to_string()),
|
||||||
|
};
|
||||||
|
let json = serde_json::to_string(&event).unwrap();
|
||||||
|
let parsed: serde_json::Value = serde_json::from_str(&json).unwrap();
|
||||||
|
assert_eq!(parsed["type"], "auth_required");
|
||||||
|
assert_eq!(parsed["extension_name"], "notion");
|
||||||
|
assert_eq!(parsed["instructions"], "Get your token from...");
|
||||||
|
assert!(parsed.get("auth_url").is_none());
|
||||||
|
assert_eq!(parsed["setup_url"], "https://notion.so/integrations");
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_sse_auth_completed_serialize() {
|
||||||
|
let event = SseEvent::AuthCompleted {
|
||||||
|
extension_name: "notion".to_string(),
|
||||||
|
success: true,
|
||||||
|
message: "notion authenticated (3 tools loaded)".to_string(),
|
||||||
|
};
|
||||||
|
let json = serde_json::to_string(&event).unwrap();
|
||||||
|
let parsed: serde_json::Value = serde_json::from_str(&json).unwrap();
|
||||||
|
assert_eq!(parsed["type"], "auth_completed");
|
||||||
|
assert_eq!(parsed["extension_name"], "notion");
|
||||||
|
assert_eq!(parsed["success"], true);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_ws_server_from_sse_auth_required() {
|
||||||
|
let sse = SseEvent::AuthRequired {
|
||||||
|
extension_name: "openai".to_string(),
|
||||||
|
instructions: Some("Enter API key".to_string()),
|
||||||
|
auth_url: None,
|
||||||
|
setup_url: None,
|
||||||
|
};
|
||||||
|
let ws = WsServerMessage::from_sse_event(&sse);
|
||||||
|
match ws {
|
||||||
|
WsServerMessage::Event { event_type, data } => {
|
||||||
|
assert_eq!(event_type, "auth_required");
|
||||||
|
assert_eq!(data["extension_name"], "openai");
|
||||||
|
}
|
||||||
|
_ => panic!("Expected Event variant"),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_ws_server_from_sse_auth_completed() {
|
||||||
|
let sse = SseEvent::AuthCompleted {
|
||||||
|
extension_name: "slack".to_string(),
|
||||||
|
success: false,
|
||||||
|
message: "Invalid token".to_string(),
|
||||||
|
};
|
||||||
|
let ws = WsServerMessage::from_sse_event(&sse);
|
||||||
|
match ws {
|
||||||
|
WsServerMessage::Event { event_type, data } => {
|
||||||
|
assert_eq!(event_type, "auth_completed");
|
||||||
|
assert_eq!(data["success"], false);
|
||||||
|
}
|
||||||
|
_ => panic!("Expected Event variant"),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_auth_token_request_deserialize() {
|
||||||
|
let json = r#"{"extension_name":"telegram","token":"bot12345"}"#;
|
||||||
|
let req: AuthTokenRequest = serde_json::from_str(json).unwrap();
|
||||||
|
assert_eq!(req.extension_name, "telegram");
|
||||||
|
assert_eq!(req.token, "bot12345");
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_auth_cancel_request_deserialize() {
|
||||||
|
let json = r#"{"extension_name":"telegram"}"#;
|
||||||
|
let req: AuthCancelRequest = serde_json::from_str(json).unwrap();
|
||||||
|
assert_eq!(req.extension_name, "telegram");
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
+86
-5
@@ -71,8 +71,17 @@ pub async fn handle_ws_connection(socket: WebSocket, state: Arc<GatewayState>) {
|
|||||||
}
|
}
|
||||||
let tracker_for_drop = state.ws_tracker.clone();
|
let tracker_for_drop = state.ws_tracker.clone();
|
||||||
|
|
||||||
// Subscribe to broadcast events (same source as SSE)
|
// Subscribe to broadcast events (same source as SSE).
|
||||||
let mut event_stream = Box::pin(state.sse.subscribe_raw());
|
// Reject if we've hit the connection limit.
|
||||||
|
let Some(raw_stream) = state.sse.subscribe_raw() else {
|
||||||
|
tracing::warn!("WebSocket rejected: too many connections");
|
||||||
|
// Decrement the WS tracker we already incremented above.
|
||||||
|
if let Some(ref tracker) = tracker_for_drop {
|
||||||
|
tracker.decrement();
|
||||||
|
}
|
||||||
|
return;
|
||||||
|
};
|
||||||
|
let mut event_stream = Box::pin(raw_stream);
|
||||||
|
|
||||||
// Channel for the sender task to receive messages from both
|
// Channel for the sender task to receive messages from both
|
||||||
// the broadcast stream and any direct sends (like Pong)
|
// the broadcast stream and any direct sends (like Pong)
|
||||||
@@ -170,7 +179,11 @@ async fn handle_client_message(
|
|||||||
.await;
|
.await;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
WsClientMessage::Approval { request_id, action } => {
|
WsClientMessage::Approval {
|
||||||
|
request_id,
|
||||||
|
action,
|
||||||
|
thread_id,
|
||||||
|
} => {
|
||||||
let (approved, always) = match action.as_str() {
|
let (approved, always) = match action.as_str() {
|
||||||
"approve" => (true, false),
|
"approve" => (true, false),
|
||||||
"always" => (true, true),
|
"always" => (true, true),
|
||||||
@@ -214,12 +227,71 @@ async fn handle_client_message(
|
|||||||
}
|
}
|
||||||
};
|
};
|
||||||
|
|
||||||
let msg = IncomingMessage::new("gateway", user_id, content);
|
let mut msg = IncomingMessage::new("gateway", user_id, content);
|
||||||
|
if let Some(ref tid) = thread_id {
|
||||||
|
msg = msg.with_thread(tid);
|
||||||
|
}
|
||||||
let tx_guard = state.msg_tx.read().await;
|
let tx_guard = state.msg_tx.read().await;
|
||||||
if let Some(ref tx) = *tx_guard {
|
if let Some(ref tx) = *tx_guard {
|
||||||
let _ = tx.send(msg).await;
|
let _ = tx.send(msg).await;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
WsClientMessage::AuthToken {
|
||||||
|
extension_name,
|
||||||
|
token,
|
||||||
|
} => {
|
||||||
|
if let Some(ref ext_mgr) = state.extension_manager {
|
||||||
|
match ext_mgr.auth(&extension_name, Some(&token)).await {
|
||||||
|
Ok(result) if result.status == "authenticated" => {
|
||||||
|
let msg = match ext_mgr.activate(&extension_name).await {
|
||||||
|
Ok(r) => format!(
|
||||||
|
"{} authenticated ({} tools loaded)",
|
||||||
|
extension_name,
|
||||||
|
r.tools_loaded.len()
|
||||||
|
),
|
||||||
|
Err(e) => format!(
|
||||||
|
"{} authenticated but activation failed: {}",
|
||||||
|
extension_name, e
|
||||||
|
),
|
||||||
|
};
|
||||||
|
crate::channels::web::server::clear_auth_mode(state).await;
|
||||||
|
state
|
||||||
|
.sse
|
||||||
|
.broadcast(crate::channels::web::types::SseEvent::AuthCompleted {
|
||||||
|
extension_name,
|
||||||
|
success: true,
|
||||||
|
message: msg,
|
||||||
|
});
|
||||||
|
}
|
||||||
|
Ok(result) => {
|
||||||
|
state
|
||||||
|
.sse
|
||||||
|
.broadcast(crate::channels::web::types::SseEvent::AuthRequired {
|
||||||
|
extension_name,
|
||||||
|
instructions: result.instructions,
|
||||||
|
auth_url: result.auth_url,
|
||||||
|
setup_url: result.setup_url,
|
||||||
|
});
|
||||||
|
}
|
||||||
|
Err(e) => {
|
||||||
|
let _ = direct_tx
|
||||||
|
.send(WsServerMessage::Error {
|
||||||
|
message: format!("Auth failed: {}", e),
|
||||||
|
})
|
||||||
|
.await;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
} else {
|
||||||
|
let _ = direct_tx
|
||||||
|
.send(WsServerMessage::Error {
|
||||||
|
message: "Extension manager not available".to_string(),
|
||||||
|
})
|
||||||
|
.await;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
WsClientMessage::AuthCancel { .. } => {
|
||||||
|
crate::channels::web::server::clear_auth_mode(state).await;
|
||||||
|
}
|
||||||
WsClientMessage::Ping => {
|
WsClientMessage::Ping => {
|
||||||
let _ = direct_tx.send(WsServerMessage::Pong).await;
|
let _ = direct_tx.send(WsServerMessage::Pong).await;
|
||||||
}
|
}
|
||||||
@@ -328,6 +400,7 @@ mod tests {
|
|||||||
WsClientMessage::Approval {
|
WsClientMessage::Approval {
|
||||||
request_id: request_id.to_string(),
|
request_id: request_id.to_string(),
|
||||||
action: "approve".to_string(),
|
action: "approve".to_string(),
|
||||||
|
thread_id: Some("thread-42".to_string()),
|
||||||
},
|
},
|
||||||
&state,
|
&state,
|
||||||
"user1",
|
"user1",
|
||||||
@@ -338,6 +411,8 @@ mod tests {
|
|||||||
let incoming = agent_rx.recv().await.unwrap();
|
let incoming = agent_rx.recv().await.unwrap();
|
||||||
// The content should be a serialized ExecApproval
|
// The content should be a serialized ExecApproval
|
||||||
assert!(incoming.content.contains("ExecApproval"));
|
assert!(incoming.content.contains("ExecApproval"));
|
||||||
|
// Thread should be forwarded onto the IncomingMessage.
|
||||||
|
assert_eq!(incoming.thread_id.as_deref(), Some("thread-42"));
|
||||||
}
|
}
|
||||||
|
|
||||||
#[tokio::test]
|
#[tokio::test]
|
||||||
@@ -349,6 +424,7 @@ mod tests {
|
|||||||
WsClientMessage::Approval {
|
WsClientMessage::Approval {
|
||||||
request_id: Uuid::new_v4().to_string(),
|
request_id: Uuid::new_v4().to_string(),
|
||||||
action: "maybe".to_string(),
|
action: "maybe".to_string(),
|
||||||
|
thread_id: None,
|
||||||
},
|
},
|
||||||
&state,
|
&state,
|
||||||
"user1",
|
"user1",
|
||||||
@@ -374,6 +450,7 @@ mod tests {
|
|||||||
WsClientMessage::Approval {
|
WsClientMessage::Approval {
|
||||||
request_id: "not-a-uuid".to_string(),
|
request_id: "not-a-uuid".to_string(),
|
||||||
action: "approve".to_string(),
|
action: "approve".to_string(),
|
||||||
|
thread_id: None,
|
||||||
},
|
},
|
||||||
&state,
|
&state,
|
||||||
"user1",
|
"user1",
|
||||||
@@ -398,14 +475,18 @@ mod tests {
|
|||||||
msg_tx: tokio::sync::RwLock::new(msg_tx),
|
msg_tx: tokio::sync::RwLock::new(msg_tx),
|
||||||
sse: SseManager::new(),
|
sse: SseManager::new(),
|
||||||
workspace: None,
|
workspace: None,
|
||||||
context_manager: None,
|
|
||||||
session_manager: None,
|
session_manager: None,
|
||||||
log_broadcaster: None,
|
log_broadcaster: None,
|
||||||
extension_manager: None,
|
extension_manager: None,
|
||||||
tool_registry: None,
|
tool_registry: None,
|
||||||
|
store: None,
|
||||||
|
job_manager: None,
|
||||||
|
prompt_queue: None,
|
||||||
user_id: "test".to_string(),
|
user_id: "test".to_string(),
|
||||||
shutdown_tx: tokio::sync::RwLock::new(None),
|
shutdown_tx: tokio::sync::RwLock::new(None),
|
||||||
ws_tracker: Some(Arc::new(WsConnectionTracker::new())),
|
ws_tracker: Some(Arc::new(WsConnectionTracker::new())),
|
||||||
|
llm_provider: None,
|
||||||
|
chat_rate_limiter: crate::channels::web::server::RateLimiter::new(30, 60),
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
+96
-58
@@ -1,6 +1,9 @@
|
|||||||
//! Configuration management CLI commands.
|
//! Configuration management CLI commands.
|
||||||
//!
|
//!
|
||||||
//! Commands for viewing and modifying settings.
|
//! Commands for viewing and modifying settings.
|
||||||
|
//! Settings are stored in the database (env > DB > default).
|
||||||
|
|
||||||
|
use std::sync::Arc;
|
||||||
|
|
||||||
use clap::Subcommand;
|
use clap::Subcommand;
|
||||||
|
|
||||||
@@ -36,41 +39,81 @@ pub enum ConfigCommand {
|
|||||||
path: String,
|
path: String,
|
||||||
},
|
},
|
||||||
|
|
||||||
/// Show the settings file path
|
/// Show the settings storage info
|
||||||
Path,
|
Path,
|
||||||
}
|
}
|
||||||
|
|
||||||
/// Run a config command.
|
/// Run a config command.
|
||||||
pub fn run_config_command(cmd: ConfigCommand) -> anyhow::Result<()> {
|
///
|
||||||
match cmd {
|
/// Connects to the database to read/write settings. Falls back to disk
|
||||||
ConfigCommand::List { filter } => list_settings(filter),
|
/// if the database is not available.
|
||||||
ConfigCommand::Get { path } => get_setting(&path),
|
pub async fn run_config_command(cmd: ConfigCommand) -> anyhow::Result<()> {
|
||||||
ConfigCommand::Set { path, value } => set_setting(&path, &value),
|
// Try to connect to the DB for settings access
|
||||||
ConfigCommand::Reset { path } => reset_setting(&path),
|
let db: Option<Arc<dyn crate::db::Database>> = match connect_db().await {
|
||||||
ConfigCommand::Path => show_path(),
|
Ok(d) => Some(d),
|
||||||
|
Err(e) => {
|
||||||
|
eprintln!(
|
||||||
|
"Warning: Could not connect to database ({}), using disk fallback",
|
||||||
|
e
|
||||||
|
);
|
||||||
|
None
|
||||||
}
|
}
|
||||||
|
};
|
||||||
|
|
||||||
|
let db_ref = db.as_deref();
|
||||||
|
match cmd {
|
||||||
|
ConfigCommand::List { filter } => list_settings(db_ref, filter).await,
|
||||||
|
ConfigCommand::Get { path } => get_setting(db_ref, &path).await,
|
||||||
|
ConfigCommand::Set { path, value } => set_setting(db_ref, &path, &value).await,
|
||||||
|
ConfigCommand::Reset { path } => reset_setting(db_ref, &path).await,
|
||||||
|
ConfigCommand::Path => show_path(db_ref.is_some()),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Bootstrap a DB connection for config commands (backend-agnostic).
|
||||||
|
async fn connect_db() -> anyhow::Result<Arc<dyn crate::db::Database>> {
|
||||||
|
let config = crate::config::Config::from_env()
|
||||||
|
.await
|
||||||
|
.map_err(|e| anyhow::anyhow!("{}", e))?;
|
||||||
|
crate::db::connect_from_config(&config.database)
|
||||||
|
.await
|
||||||
|
.map_err(|e| anyhow::anyhow!("{}", e))
|
||||||
|
}
|
||||||
|
|
||||||
|
const DEFAULT_USER_ID: &str = "default";
|
||||||
|
|
||||||
|
/// Load settings: DB if available, else disk.
|
||||||
|
async fn load_settings(store: Option<&dyn crate::db::Database>) -> Settings {
|
||||||
|
if let Some(store) = store {
|
||||||
|
match store.get_all_settings(DEFAULT_USER_ID).await {
|
||||||
|
Ok(map) if !map.is_empty() => return Settings::from_db_map(&map),
|
||||||
|
_ => {}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
Settings::default()
|
||||||
}
|
}
|
||||||
|
|
||||||
/// List all settings.
|
/// List all settings.
|
||||||
fn list_settings(filter: Option<String>) -> anyhow::Result<()> {
|
async fn list_settings(
|
||||||
let settings = Settings::load();
|
store: Option<&dyn crate::db::Database>,
|
||||||
|
filter: Option<String>,
|
||||||
|
) -> anyhow::Result<()> {
|
||||||
|
let settings = load_settings(store).await;
|
||||||
let all = settings.list();
|
let all = settings.list();
|
||||||
|
|
||||||
// Find the longest key for alignment
|
|
||||||
let max_key_len = all.iter().map(|(k, _)| k.len()).max().unwrap_or(0);
|
let max_key_len = all.iter().map(|(k, _)| k.len()).max().unwrap_or(0);
|
||||||
|
|
||||||
println!("Settings:");
|
let source = if store.is_some() { "database" } else { "disk" };
|
||||||
|
println!("Settings (source: {}):", source);
|
||||||
println!();
|
println!();
|
||||||
|
|
||||||
for (key, value) in all {
|
for (key, value) in all {
|
||||||
// Skip if filter is set and doesn't match
|
if let Some(ref f) = filter
|
||||||
if let Some(ref f) = filter {
|
&& !key.starts_with(f)
|
||||||
if !key.starts_with(f) {
|
{
|
||||||
continue;
|
continue;
|
||||||
}
|
}
|
||||||
}
|
|
||||||
|
|
||||||
// Truncate long values for display
|
|
||||||
let display_value = if value.len() > 60 {
|
let display_value = if value.len() > 60 {
|
||||||
format!("{}...", &value[..57])
|
format!("{}...", &value[..57])
|
||||||
} else {
|
} else {
|
||||||
@@ -84,8 +127,8 @@ fn list_settings(filter: Option<String>) -> anyhow::Result<()> {
|
|||||||
}
|
}
|
||||||
|
|
||||||
/// Get a specific setting.
|
/// Get a specific setting.
|
||||||
fn get_setting(path: &str) -> anyhow::Result<()> {
|
async fn get_setting(store: Option<&dyn crate::db::Database>, path: &str) -> anyhow::Result<()> {
|
||||||
let settings = Settings::load();
|
let settings = load_settings(store).await;
|
||||||
|
|
||||||
match settings.get(path) {
|
match settings.get(path) {
|
||||||
Some(value) => {
|
Some(value) => {
|
||||||
@@ -99,68 +142,63 @@ fn get_setting(path: &str) -> anyhow::Result<()> {
|
|||||||
}
|
}
|
||||||
|
|
||||||
/// Set a setting value.
|
/// Set a setting value.
|
||||||
fn set_setting(path: &str, value: &str) -> anyhow::Result<()> {
|
async fn set_setting(
|
||||||
let mut settings = Settings::load();
|
store: Option<&dyn crate::db::Database>,
|
||||||
|
path: &str,
|
||||||
|
value: &str,
|
||||||
|
) -> anyhow::Result<()> {
|
||||||
|
let mut settings = load_settings(store).await;
|
||||||
|
|
||||||
// Try to set the value
|
|
||||||
settings
|
settings
|
||||||
.set(path, value)
|
.set(path, value)
|
||||||
.map_err(|e| anyhow::anyhow!("{}", e))?;
|
.map_err(|e| anyhow::anyhow!("{}", e))?;
|
||||||
|
|
||||||
// Save to disk
|
let store = store.ok_or_else(|| {
|
||||||
settings.save()?;
|
anyhow::anyhow!("Database connection required to save settings. Check DATABASE_URL.")
|
||||||
|
})?;
|
||||||
|
let json_value = match serde_json::from_str::<serde_json::Value>(value) {
|
||||||
|
Ok(v) => v,
|
||||||
|
Err(_) => serde_json::Value::String(value.to_string()),
|
||||||
|
};
|
||||||
|
store
|
||||||
|
.set_setting(DEFAULT_USER_ID, path, &json_value)
|
||||||
|
.await
|
||||||
|
.map_err(|e| anyhow::anyhow!("Failed to save to database: {}", e))?;
|
||||||
|
|
||||||
println!("Set {} = {}", path, value);
|
println!("Set {} = {}", path, value);
|
||||||
Ok(())
|
Ok(())
|
||||||
}
|
}
|
||||||
|
|
||||||
/// Reset a setting to default.
|
/// Reset a setting to default.
|
||||||
fn reset_setting(path: &str) -> anyhow::Result<()> {
|
async fn reset_setting(store: Option<&dyn crate::db::Database>, path: &str) -> anyhow::Result<()> {
|
||||||
let mut settings = Settings::load();
|
|
||||||
|
|
||||||
// Get the default value for display
|
|
||||||
let default = Settings::default();
|
let default = Settings::default();
|
||||||
let default_value = default
|
let default_value = default
|
||||||
.get(path)
|
.get(path)
|
||||||
.ok_or_else(|| anyhow::anyhow!("Unknown setting: {}", path))?;
|
.ok_or_else(|| anyhow::anyhow!("Unknown setting: {}", path))?;
|
||||||
|
|
||||||
// Reset it
|
let store = store.ok_or_else(|| {
|
||||||
settings.reset(path).map_err(|e| anyhow::anyhow!("{}", e))?;
|
anyhow::anyhow!("Database connection required to reset settings. Check DATABASE_URL.")
|
||||||
|
})?;
|
||||||
// Save to disk
|
store
|
||||||
settings.save()?;
|
.delete_setting(DEFAULT_USER_ID, path)
|
||||||
|
.await
|
||||||
|
.map_err(|e| anyhow::anyhow!("Failed to delete setting from database: {}", e))?;
|
||||||
|
|
||||||
println!("Reset {} to default: {}", path, default_value);
|
println!("Reset {} to default: {}", path, default_value);
|
||||||
Ok(())
|
Ok(())
|
||||||
}
|
}
|
||||||
|
|
||||||
/// Show the settings file path.
|
/// Show the settings storage info.
|
||||||
fn show_path() -> anyhow::Result<()> {
|
fn show_path(has_db: bool) -> anyhow::Result<()> {
|
||||||
let path = Settings::default_path();
|
if has_db {
|
||||||
println!("{}", path.display());
|
println!("Settings stored in: database (settings table)");
|
||||||
|
|
||||||
if path.exists() {
|
|
||||||
let metadata = std::fs::metadata(&path)?;
|
|
||||||
println!(" Size: {} bytes", metadata.len());
|
|
||||||
if let Ok(modified) = metadata.modified() {
|
|
||||||
use std::time::SystemTime;
|
|
||||||
let duration = SystemTime::now()
|
|
||||||
.duration_since(modified)
|
|
||||||
.unwrap_or_default();
|
|
||||||
let secs = duration.as_secs();
|
|
||||||
if secs < 60 {
|
|
||||||
println!(" Modified: {} seconds ago", secs);
|
|
||||||
} else if secs < 3600 {
|
|
||||||
println!(" Modified: {} minutes ago", secs / 60);
|
|
||||||
} else if secs < 86400 {
|
|
||||||
println!(" Modified: {} hours ago", secs / 3600);
|
|
||||||
} else {
|
} else {
|
||||||
println!(" Modified: {} days ago", secs / 86400);
|
println!("Settings stored in: PostgreSQL (not connected, using defaults)");
|
||||||
}
|
|
||||||
}
|
|
||||||
} else {
|
|
||||||
println!(" (does not exist, using defaults)");
|
|
||||||
}
|
}
|
||||||
|
println!(
|
||||||
|
"Env config: {}",
|
||||||
|
crate::bootstrap::ironclaw_env_path().display()
|
||||||
|
);
|
||||||
|
|
||||||
Ok(())
|
Ok(())
|
||||||
}
|
}
|
||||||
|
|||||||
+113
-17
@@ -8,14 +8,14 @@ use std::sync::Arc;
|
|||||||
use clap::Subcommand;
|
use clap::Subcommand;
|
||||||
|
|
||||||
use crate::config::Config;
|
use crate::config::Config;
|
||||||
use crate::history::Store;
|
use crate::db::Database;
|
||||||
use crate::secrets::{PostgresSecretsStore, SecretsCrypto, SecretsStore};
|
#[cfg(feature = "postgres")]
|
||||||
|
use crate::secrets::PostgresSecretsStore;
|
||||||
|
use crate::secrets::{SecretsCrypto, SecretsStore};
|
||||||
use crate::tools::mcp::{
|
use crate::tools::mcp::{
|
||||||
McpClient, McpServerConfig, McpSessionManager, OAuthConfig,
|
McpClient, McpServerConfig, McpSessionManager, OAuthConfig,
|
||||||
auth::{authorize_mcp_server, is_authenticated},
|
auth::{authorize_mcp_server, is_authenticated},
|
||||||
config::{
|
config::{self, McpServersFile},
|
||||||
add_mcp_server, get_mcp_server, load_mcp_servers, remove_mcp_server, save_mcp_servers,
|
|
||||||
},
|
|
||||||
};
|
};
|
||||||
|
|
||||||
#[derive(Subcommand, Debug, Clone)]
|
#[derive(Subcommand, Debug, Clone)]
|
||||||
@@ -173,8 +173,11 @@ async fn add_server(
|
|||||||
// Validate
|
// Validate
|
||||||
config.validate()?;
|
config.validate()?;
|
||||||
|
|
||||||
// Save
|
// Save (DB if available, else disk)
|
||||||
add_mcp_server(config).await?;
|
let db = connect_db().await;
|
||||||
|
let mut servers = load_servers(db.as_deref()).await?;
|
||||||
|
servers.upsert(config);
|
||||||
|
save_servers(db.as_deref(), &servers).await?;
|
||||||
|
|
||||||
println!();
|
println!();
|
||||||
println!(" ✓ Added MCP server '{}'", name);
|
println!(" ✓ Added MCP server '{}'", name);
|
||||||
@@ -192,7 +195,12 @@ async fn add_server(
|
|||||||
|
|
||||||
/// Remove an MCP server.
|
/// Remove an MCP server.
|
||||||
async fn remove_server(name: String) -> anyhow::Result<()> {
|
async fn remove_server(name: String) -> anyhow::Result<()> {
|
||||||
remove_mcp_server(&name).await?;
|
let db = connect_db().await;
|
||||||
|
let mut servers = load_servers(db.as_deref()).await?;
|
||||||
|
if !servers.remove(&name) {
|
||||||
|
anyhow::bail!("Server '{}' not found", name);
|
||||||
|
}
|
||||||
|
save_servers(db.as_deref(), &servers).await?;
|
||||||
|
|
||||||
println!();
|
println!();
|
||||||
println!(" ✓ Removed MCP server '{}'", name);
|
println!(" ✓ Removed MCP server '{}'", name);
|
||||||
@@ -203,7 +211,8 @@ async fn remove_server(name: String) -> anyhow::Result<()> {
|
|||||||
|
|
||||||
/// List configured MCP servers.
|
/// List configured MCP servers.
|
||||||
async fn list_servers(verbose: bool) -> anyhow::Result<()> {
|
async fn list_servers(verbose: bool) -> anyhow::Result<()> {
|
||||||
let servers = load_mcp_servers().await?;
|
let db = connect_db().await;
|
||||||
|
let servers = load_servers(db.as_deref()).await?;
|
||||||
|
|
||||||
if servers.servers.is_empty() {
|
if servers.servers.is_empty() {
|
||||||
println!();
|
println!();
|
||||||
@@ -261,7 +270,12 @@ async fn list_servers(verbose: bool) -> anyhow::Result<()> {
|
|||||||
/// Authenticate with an MCP server.
|
/// Authenticate with an MCP server.
|
||||||
async fn auth_server(name: String, user_id: String) -> anyhow::Result<()> {
|
async fn auth_server(name: String, user_id: String) -> anyhow::Result<()> {
|
||||||
// Get server config
|
// Get server config
|
||||||
let server = get_mcp_server(&name).await?;
|
let db = connect_db().await;
|
||||||
|
let servers = load_servers(db.as_deref()).await?;
|
||||||
|
let server = servers
|
||||||
|
.get(&name)
|
||||||
|
.cloned()
|
||||||
|
.ok_or_else(|| anyhow::anyhow!("Server '{}' not found", name))?;
|
||||||
|
|
||||||
// Initialize secrets store
|
// Initialize secrets store
|
||||||
let secrets = get_secrets_store().await?;
|
let secrets = get_secrets_store().await?;
|
||||||
@@ -329,7 +343,12 @@ async fn auth_server(name: String, user_id: String) -> anyhow::Result<()> {
|
|||||||
/// Test connection to an MCP server.
|
/// Test connection to an MCP server.
|
||||||
async fn test_server(name: String, user_id: String) -> anyhow::Result<()> {
|
async fn test_server(name: String, user_id: String) -> anyhow::Result<()> {
|
||||||
// Get server config
|
// Get server config
|
||||||
let server = get_mcp_server(&name).await?;
|
let db = connect_db().await;
|
||||||
|
let servers = load_servers(db.as_deref()).await?;
|
||||||
|
let server = servers
|
||||||
|
.get(&name)
|
||||||
|
.cloned()
|
||||||
|
.ok_or_else(|| anyhow::anyhow!("Server '{}' not found", name))?;
|
||||||
|
|
||||||
println!();
|
println!();
|
||||||
println!(" Testing connection to '{}'...", name);
|
println!(" Testing connection to '{}'...", name);
|
||||||
@@ -420,7 +439,8 @@ async fn test_server(name: String, user_id: String) -> anyhow::Result<()> {
|
|||||||
|
|
||||||
/// Toggle server enabled/disabled state.
|
/// Toggle server enabled/disabled state.
|
||||||
async fn toggle_server(name: String, enable: bool, disable: bool) -> anyhow::Result<()> {
|
async fn toggle_server(name: String, enable: bool, disable: bool) -> anyhow::Result<()> {
|
||||||
let mut servers = load_mcp_servers().await?;
|
let db = connect_db().await;
|
||||||
|
let mut servers = load_servers(db.as_deref()).await?;
|
||||||
|
|
||||||
let server = servers
|
let server = servers
|
||||||
.get_mut(&name)
|
.get_mut(&name)
|
||||||
@@ -435,7 +455,7 @@ async fn toggle_server(name: String, enable: bool, disable: bool) -> anyhow::Res
|
|||||||
};
|
};
|
||||||
|
|
||||||
server.enabled = new_state;
|
server.enabled = new_state;
|
||||||
save_mcp_servers(&servers).await?;
|
save_servers(db.as_deref(), &servers).await?;
|
||||||
|
|
||||||
let status = if new_state { "enabled" } else { "disabled" };
|
let status = if new_state { "enabled" } else { "disabled" };
|
||||||
println!();
|
println!();
|
||||||
@@ -445,9 +465,38 @@ async fn toggle_server(name: String, enable: bool, disable: bool) -> anyhow::Res
|
|||||||
Ok(())
|
Ok(())
|
||||||
}
|
}
|
||||||
|
|
||||||
|
const DEFAULT_USER_ID: &str = "default";
|
||||||
|
|
||||||
|
/// Try to connect to the database (backend-agnostic).
|
||||||
|
async fn connect_db() -> Option<Arc<dyn Database>> {
|
||||||
|
let config = Config::from_env().await.ok()?;
|
||||||
|
crate::db::connect_from_config(&config.database).await.ok()
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Load MCP servers (DB if available, else disk).
|
||||||
|
async fn load_servers(db: Option<&dyn Database>) -> Result<McpServersFile, config::ConfigError> {
|
||||||
|
if let Some(db) = db {
|
||||||
|
config::load_mcp_servers_from_db(db, DEFAULT_USER_ID).await
|
||||||
|
} else {
|
||||||
|
config::load_mcp_servers().await
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Save MCP servers (DB if available, else disk).
|
||||||
|
async fn save_servers(
|
||||||
|
db: Option<&dyn Database>,
|
||||||
|
servers: &McpServersFile,
|
||||||
|
) -> Result<(), config::ConfigError> {
|
||||||
|
if let Some(db) = db {
|
||||||
|
config::save_mcp_servers_to_db(db, DEFAULT_USER_ID, servers).await
|
||||||
|
} else {
|
||||||
|
config::save_mcp_servers(servers).await
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
/// Initialize and return the secrets store.
|
/// Initialize and return the secrets store.
|
||||||
async fn get_secrets_store() -> anyhow::Result<Arc<dyn SecretsStore + Send + Sync>> {
|
async fn get_secrets_store() -> anyhow::Result<Arc<dyn SecretsStore + Send + Sync>> {
|
||||||
let config = Config::from_env()?;
|
let config = Config::from_env().await?;
|
||||||
|
|
||||||
let master_key = config.secrets.master_key().ok_or_else(|| {
|
let master_key = config.secrets.master_key().ok_or_else(|| {
|
||||||
anyhow::anyhow!(
|
anyhow::anyhow!(
|
||||||
@@ -455,16 +504,63 @@ async fn get_secrets_store() -> anyhow::Result<Arc<dyn SecretsStore + Send + Syn
|
|||||||
)
|
)
|
||||||
})?;
|
})?;
|
||||||
|
|
||||||
let store = Store::new(&config.database).await?;
|
|
||||||
store.run_migrations().await?;
|
|
||||||
|
|
||||||
let crypto = SecretsCrypto::new(master_key.clone())?;
|
let crypto = SecretsCrypto::new(master_key.clone())?;
|
||||||
|
|
||||||
|
#[cfg(feature = "postgres")]
|
||||||
|
{
|
||||||
|
let store = crate::history::Store::new(&config.database).await?;
|
||||||
|
store.run_migrations().await?;
|
||||||
Ok(Arc::new(PostgresSecretsStore::new(
|
Ok(Arc::new(PostgresSecretsStore::new(
|
||||||
store.pool(),
|
store.pool(),
|
||||||
Arc::new(crypto),
|
Arc::new(crypto),
|
||||||
)))
|
)))
|
||||||
}
|
}
|
||||||
|
|
||||||
|
#[cfg(all(feature = "libsql", not(feature = "postgres")))]
|
||||||
|
{
|
||||||
|
use crate::db::Database as _;
|
||||||
|
use crate::db::libsql_backend::LibSqlBackend;
|
||||||
|
use secrecy::ExposeSecret as _;
|
||||||
|
|
||||||
|
let default_path = crate::config::default_libsql_path();
|
||||||
|
let db_path = config
|
||||||
|
.database
|
||||||
|
.libsql_path
|
||||||
|
.as_deref()
|
||||||
|
.unwrap_or(&default_path);
|
||||||
|
|
||||||
|
let backend = if let Some(ref url) = config.database.libsql_url {
|
||||||
|
let token = config.database.libsql_auth_token.as_ref().ok_or_else(|| {
|
||||||
|
anyhow::anyhow!("LIBSQL_AUTH_TOKEN is required when LIBSQL_URL is set")
|
||||||
|
})?;
|
||||||
|
LibSqlBackend::new_remote_replica(db_path, url, token.expose_secret())
|
||||||
|
.await
|
||||||
|
.map_err(|e| anyhow::anyhow!("{}", e))?
|
||||||
|
} else {
|
||||||
|
LibSqlBackend::new_local(db_path)
|
||||||
|
.await
|
||||||
|
.map_err(|e| anyhow::anyhow!("{}", e))?
|
||||||
|
};
|
||||||
|
backend
|
||||||
|
.run_migrations()
|
||||||
|
.await
|
||||||
|
.map_err(|e| anyhow::anyhow!("{}", e))?;
|
||||||
|
|
||||||
|
return Ok(Arc::new(crate::secrets::LibSqlSecretsStore::new(
|
||||||
|
backend.shared_db(),
|
||||||
|
Arc::new(crypto),
|
||||||
|
)));
|
||||||
|
}
|
||||||
|
|
||||||
|
#[cfg(not(any(feature = "postgres", feature = "libsql")))]
|
||||||
|
{
|
||||||
|
let _ = crypto;
|
||||||
|
anyhow::bail!(
|
||||||
|
"No database backend available for secrets. Enable 'postgres' or 'libsql' feature."
|
||||||
|
);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
#[cfg(test)]
|
#[cfg(test)]
|
||||||
mod tests {
|
mod tests {
|
||||||
use super::*;
|
use super::*;
|
||||||
|
|||||||
+26
-1
@@ -9,6 +9,30 @@ use clap::Subcommand;
|
|||||||
|
|
||||||
use crate::workspace::{EmbeddingProvider, SearchConfig, Workspace};
|
use crate::workspace::{EmbeddingProvider, SearchConfig, Workspace};
|
||||||
|
|
||||||
|
/// Run a memory command using the Database trait (works with any backend).
|
||||||
|
pub async fn run_memory_command_with_db(
|
||||||
|
cmd: MemoryCommand,
|
||||||
|
db: std::sync::Arc<dyn crate::db::Database>,
|
||||||
|
embeddings: Option<Arc<dyn EmbeddingProvider>>,
|
||||||
|
) -> anyhow::Result<()> {
|
||||||
|
let mut workspace = Workspace::new_with_db("default", db);
|
||||||
|
if let Some(emb) = embeddings {
|
||||||
|
workspace = workspace.with_embeddings(emb);
|
||||||
|
}
|
||||||
|
|
||||||
|
match cmd {
|
||||||
|
MemoryCommand::Search { query, limit } => search(&workspace, &query, limit).await,
|
||||||
|
MemoryCommand::Read { path } => read(&workspace, &path).await,
|
||||||
|
MemoryCommand::Write {
|
||||||
|
path,
|
||||||
|
content,
|
||||||
|
append,
|
||||||
|
} => write(&workspace, &path, content, append).await,
|
||||||
|
MemoryCommand::Tree { path, depth } => tree(&workspace, &path, depth).await,
|
||||||
|
MemoryCommand::Status => status(&workspace).await,
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
#[derive(Subcommand, Debug, Clone)]
|
#[derive(Subcommand, Debug, Clone)]
|
||||||
pub enum MemoryCommand {
|
pub enum MemoryCommand {
|
||||||
/// Search workspace memory (hybrid full-text + semantic)
|
/// Search workspace memory (hybrid full-text + semantic)
|
||||||
@@ -55,7 +79,8 @@ pub enum MemoryCommand {
|
|||||||
Status,
|
Status,
|
||||||
}
|
}
|
||||||
|
|
||||||
/// Run a memory command.
|
/// Run a memory command (PostgreSQL backend).
|
||||||
|
#[cfg(feature = "postgres")]
|
||||||
pub async fn run_memory_command(
|
pub async fn run_memory_command(
|
||||||
cmd: MemoryCommand,
|
cmd: MemoryCommand,
|
||||||
pool: deadpool_postgres::Pool,
|
pool: deadpool_postgres::Pool,
|
||||||
|
|||||||
+47
-1
@@ -12,12 +12,18 @@
|
|||||||
mod config;
|
mod config;
|
||||||
mod mcp;
|
mod mcp;
|
||||||
pub mod memory;
|
pub mod memory;
|
||||||
|
pub mod oauth_defaults;
|
||||||
|
mod pairing;
|
||||||
pub mod status;
|
pub mod status;
|
||||||
mod tool;
|
mod tool;
|
||||||
|
|
||||||
pub use config::{ConfigCommand, run_config_command};
|
pub use config::{ConfigCommand, run_config_command};
|
||||||
pub use mcp::{McpCommand, run_mcp_command};
|
pub use mcp::{McpCommand, run_mcp_command};
|
||||||
pub use memory::{MemoryCommand, run_memory_command};
|
pub use memory::MemoryCommand;
|
||||||
|
#[cfg(feature = "postgres")]
|
||||||
|
pub use memory::run_memory_command;
|
||||||
|
pub use memory::run_memory_command_with_db;
|
||||||
|
pub use pairing::{PairingCommand, run_pairing_command, run_pairing_command_with_store};
|
||||||
pub use status::run_status_command;
|
pub use status::run_status_command;
|
||||||
pub use tool::{ToolCommand, run_tool_command};
|
pub use tool::{ToolCommand, run_tool_command};
|
||||||
|
|
||||||
@@ -86,8 +92,48 @@ pub enum Command {
|
|||||||
#[command(subcommand)]
|
#[command(subcommand)]
|
||||||
Memory(MemoryCommand),
|
Memory(MemoryCommand),
|
||||||
|
|
||||||
|
/// DM pairing (approve inbound requests from unknown senders)
|
||||||
|
#[command(subcommand)]
|
||||||
|
Pairing(PairingCommand),
|
||||||
|
|
||||||
/// Show system health and diagnostics
|
/// Show system health and diagnostics
|
||||||
Status,
|
Status,
|
||||||
|
|
||||||
|
/// Run as a sandboxed worker inside a Docker container (internal use).
|
||||||
|
/// This is invoked automatically by the orchestrator, not by users directly.
|
||||||
|
Worker {
|
||||||
|
/// Job ID to execute.
|
||||||
|
#[arg(long)]
|
||||||
|
job_id: uuid::Uuid,
|
||||||
|
|
||||||
|
/// URL of the orchestrator's internal API.
|
||||||
|
#[arg(long, default_value = "http://host.docker.internal:50051")]
|
||||||
|
orchestrator_url: String,
|
||||||
|
|
||||||
|
/// Maximum iterations before stopping.
|
||||||
|
#[arg(long, default_value = "50")]
|
||||||
|
max_iterations: u32,
|
||||||
|
},
|
||||||
|
|
||||||
|
/// Run as a Claude Code bridge inside a Docker container (internal use).
|
||||||
|
/// Spawns the `claude` CLI and streams output back to the orchestrator.
|
||||||
|
ClaudeBridge {
|
||||||
|
/// Job ID to execute.
|
||||||
|
#[arg(long)]
|
||||||
|
job_id: uuid::Uuid,
|
||||||
|
|
||||||
|
/// URL of the orchestrator's internal API.
|
||||||
|
#[arg(long, default_value = "http://host.docker.internal:50051")]
|
||||||
|
orchestrator_url: String,
|
||||||
|
|
||||||
|
/// Maximum agentic turns for Claude Code.
|
||||||
|
#[arg(long, default_value = "50")]
|
||||||
|
max_turns: u32,
|
||||||
|
|
||||||
|
/// Claude model to use (e.g. "sonnet", "opus").
|
||||||
|
#[arg(long, default_value = "sonnet")]
|
||||||
|
model: String,
|
||||||
|
},
|
||||||
}
|
}
|
||||||
|
|
||||||
impl Cli {
|
impl Cli {
|
||||||
|
|||||||
@@ -0,0 +1,342 @@
|
|||||||
|
//! Shared OAuth infrastructure: built-in credentials, callback server, landing pages.
|
||||||
|
//!
|
||||||
|
//! Every OAuth flow in the codebase (WASM tool auth, MCP server auth, NEAR AI login)
|
||||||
|
//! uses the same callback port, landing page, and listener logic from this module.
|
||||||
|
//!
|
||||||
|
//! # Built-in Credentials
|
||||||
|
//!
|
||||||
|
//! Many CLI tools (gcloud, rclone, gdrive) ship with default OAuth credentials
|
||||||
|
//! so users don't need to register their own OAuth app. Google explicitly
|
||||||
|
//! documents that client_secret for "Desktop App" / "Installed App" types
|
||||||
|
//! is NOT actually secret.
|
||||||
|
//!
|
||||||
|
//! Default credentials are hardcoded below. They can be overridden at:
|
||||||
|
//!
|
||||||
|
//! - **Compile time**: Set IRONCLAW_GOOGLE_CLIENT_ID / IRONCLAW_GOOGLE_CLIENT_SECRET
|
||||||
|
//! env vars before building to replace the hardcoded defaults.
|
||||||
|
//! - **Runtime**: Users can set GOOGLE_OAUTH_CLIENT_ID / GOOGLE_OAUTH_CLIENT_SECRET
|
||||||
|
//! env vars, which take priority over built-in defaults.
|
||||||
|
|
||||||
|
use std::time::Duration;
|
||||||
|
|
||||||
|
use tokio::io::{AsyncBufReadExt, AsyncWriteExt, BufReader};
|
||||||
|
use tokio::net::TcpListener;
|
||||||
|
|
||||||
|
// ── Built-in credentials ────────────────────────────────────────────────
|
||||||
|
|
||||||
|
pub struct OAuthCredentials {
|
||||||
|
pub client_id: &'static str,
|
||||||
|
pub client_secret: &'static str,
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Google OAuth "Desktop App" credentials, shared across all Google tools.
|
||||||
|
/// Compile-time env vars override the hardcoded defaults below.
|
||||||
|
const GOOGLE_CLIENT_ID: &str = match option_env!("IRONCLAW_GOOGLE_CLIENT_ID") {
|
||||||
|
Some(v) => v,
|
||||||
|
None => "564604149681-efo25d43rs85v0tibdepsmdv5dsrhhr0.apps.googleusercontent.com",
|
||||||
|
};
|
||||||
|
const GOOGLE_CLIENT_SECRET: &str = match option_env!("IRONCLAW_GOOGLE_CLIENT_SECRET") {
|
||||||
|
Some(v) => v,
|
||||||
|
None => "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",
|
||||||
|
};
|
||||||
|
|
||||||
|
/// Returns built-in OAuth credentials for a provider, keyed by secret_name.
|
||||||
|
///
|
||||||
|
/// The secret_name comes from the tool's capabilities.json `auth.secret_name` field.
|
||||||
|
/// Returns `None` if no built-in credentials are configured for that provider.
|
||||||
|
pub fn builtin_credentials(secret_name: &str) -> Option<OAuthCredentials> {
|
||||||
|
match secret_name {
|
||||||
|
"google_oauth_token" => Some(OAuthCredentials {
|
||||||
|
client_id: GOOGLE_CLIENT_ID,
|
||||||
|
client_secret: GOOGLE_CLIENT_SECRET,
|
||||||
|
}),
|
||||||
|
_ => None,
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// ── Shared callback server ──────────────────────────────────────────────
|
||||||
|
|
||||||
|
/// Fixed port for all OAuth callbacks.
|
||||||
|
///
|
||||||
|
/// Every redirect URI registered with providers must use this port:
|
||||||
|
/// `http://localhost:9876/callback` (or `/auth/callback` for NEAR AI).
|
||||||
|
pub const OAUTH_CALLBACK_PORT: u16 = 9876;
|
||||||
|
|
||||||
|
/// Error from the OAuth callback listener.
|
||||||
|
#[derive(Debug, thiserror::Error)]
|
||||||
|
pub enum OAuthCallbackError {
|
||||||
|
#[error("Port {0} is in use (another auth flow running?): {1}")]
|
||||||
|
PortInUse(u16, String),
|
||||||
|
|
||||||
|
#[error("Authorization denied by user")]
|
||||||
|
Denied,
|
||||||
|
|
||||||
|
#[error("Timed out waiting for authorization")]
|
||||||
|
Timeout,
|
||||||
|
|
||||||
|
#[error("IO error: {0}")]
|
||||||
|
Io(String),
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Bind the OAuth callback listener on the fixed port.
|
||||||
|
///
|
||||||
|
/// Binds to IPv4 `127.0.0.1` first because callback URLs use `127.0.0.1`
|
||||||
|
/// explicitly (e.g., NEAR AI redirects to `http://127.0.0.1:9876/auth/callback`).
|
||||||
|
/// Falls back to IPv6 `[::1]` only if IPv4 binding fails for a reason other
|
||||||
|
/// than `AddrInUse`. If the port is already occupied, fails immediately.
|
||||||
|
pub async fn bind_callback_listener() -> Result<TcpListener, OAuthCallbackError> {
|
||||||
|
let ipv4_addr = format!("127.0.0.1:{}", OAUTH_CALLBACK_PORT);
|
||||||
|
match TcpListener::bind(&ipv4_addr).await {
|
||||||
|
Ok(listener) => return Ok(listener),
|
||||||
|
Err(e) if e.kind() == std::io::ErrorKind::AddrInUse => {
|
||||||
|
return Err(OAuthCallbackError::PortInUse(
|
||||||
|
OAUTH_CALLBACK_PORT,
|
||||||
|
e.to_string(),
|
||||||
|
));
|
||||||
|
}
|
||||||
|
Err(_) => {
|
||||||
|
// IPv4 not available, fall back to IPv6
|
||||||
|
}
|
||||||
|
}
|
||||||
|
TcpListener::bind(format!("[::1]:{}", OAUTH_CALLBACK_PORT))
|
||||||
|
.await
|
||||||
|
.map_err(|e| {
|
||||||
|
if e.kind() == std::io::ErrorKind::AddrInUse {
|
||||||
|
OAuthCallbackError::PortInUse(OAUTH_CALLBACK_PORT, e.to_string())
|
||||||
|
} else {
|
||||||
|
OAuthCallbackError::Io(e.to_string())
|
||||||
|
}
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Wait for an OAuth callback and extract a query parameter value.
|
||||||
|
///
|
||||||
|
/// Listens for a GET request matching `path_prefix` (e.g., "/callback" or "/auth/callback"),
|
||||||
|
/// extracts the value of `param_name` (e.g., "code" or "token"), and shows a branded
|
||||||
|
/// landing page using `display_name` (e.g., "Google", "Notion", "NEAR AI").
|
||||||
|
///
|
||||||
|
/// Times out after 5 minutes.
|
||||||
|
pub async fn wait_for_callback(
|
||||||
|
listener: TcpListener,
|
||||||
|
path_prefix: &str,
|
||||||
|
param_name: &str,
|
||||||
|
display_name: &str,
|
||||||
|
) -> Result<String, OAuthCallbackError> {
|
||||||
|
let path_prefix = path_prefix.to_string();
|
||||||
|
let param_name = param_name.to_string();
|
||||||
|
let display_name = display_name.to_string();
|
||||||
|
|
||||||
|
tokio::time::timeout(Duration::from_secs(300), async move {
|
||||||
|
loop {
|
||||||
|
let (mut socket, _) = listener
|
||||||
|
.accept()
|
||||||
|
.await
|
||||||
|
.map_err(|e| OAuthCallbackError::Io(e.to_string()))?;
|
||||||
|
|
||||||
|
let mut reader = BufReader::new(&mut socket);
|
||||||
|
let mut request_line = String::new();
|
||||||
|
reader
|
||||||
|
.read_line(&mut request_line)
|
||||||
|
.await
|
||||||
|
.map_err(|e| OAuthCallbackError::Io(e.to_string()))?;
|
||||||
|
|
||||||
|
if let Some(path) = request_line.split_whitespace().nth(1)
|
||||||
|
&& path.starts_with(&path_prefix)
|
||||||
|
&& let Some(query) = path.split('?').nth(1)
|
||||||
|
{
|
||||||
|
// Check for error first
|
||||||
|
if query.contains("error=") {
|
||||||
|
let html = landing_html(&display_name, false);
|
||||||
|
let response = format!(
|
||||||
|
"HTTP/1.1 400 Bad Request\r\n\
|
||||||
|
Content-Type: text/html; charset=utf-8\r\n\
|
||||||
|
Connection: close\r\n\
|
||||||
|
\r\n\
|
||||||
|
{}",
|
||||||
|
html
|
||||||
|
);
|
||||||
|
let _ = socket.write_all(response.as_bytes()).await;
|
||||||
|
return Err(OAuthCallbackError::Denied);
|
||||||
|
}
|
||||||
|
|
||||||
|
// Look for the target parameter
|
||||||
|
for param in query.split('&') {
|
||||||
|
let parts: Vec<&str> = param.splitn(2, '=').collect();
|
||||||
|
if parts.len() == 2 && parts[0] == param_name {
|
||||||
|
let value = urlencoding::decode(parts[1])
|
||||||
|
.unwrap_or_else(|_| parts[1].into())
|
||||||
|
.into_owned();
|
||||||
|
|
||||||
|
let html = landing_html(&display_name, true);
|
||||||
|
let response = format!(
|
||||||
|
"HTTP/1.1 200 OK\r\n\
|
||||||
|
Content-Type: text/html; charset=utf-8\r\n\
|
||||||
|
Connection: close\r\n\
|
||||||
|
\r\n\
|
||||||
|
{}",
|
||||||
|
html
|
||||||
|
);
|
||||||
|
let _ = socket.write_all(response.as_bytes()).await;
|
||||||
|
let _ = socket.shutdown().await;
|
||||||
|
|
||||||
|
return Ok(value);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// Not the callback we're looking for
|
||||||
|
let response = "HTTP/1.1 404 Not Found\r\nConnection: close\r\n\r\n";
|
||||||
|
let _ = socket.write_all(response.as_bytes()).await;
|
||||||
|
}
|
||||||
|
})
|
||||||
|
.await
|
||||||
|
.map_err(|_| OAuthCallbackError::Timeout)?
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Escape a string for safe interpolation into HTML content.
|
||||||
|
fn html_escape(s: &str) -> String {
|
||||||
|
let mut out = String::with_capacity(s.len());
|
||||||
|
for c in s.chars() {
|
||||||
|
match c {
|
||||||
|
'&' => out.push_str("&"),
|
||||||
|
'<' => out.push_str("<"),
|
||||||
|
'>' => out.push_str(">"),
|
||||||
|
'"' => out.push_str("""),
|
||||||
|
'\'' => out.push_str("'"),
|
||||||
|
_ => out.push(c),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
out
|
||||||
|
}
|
||||||
|
|
||||||
|
/// HTML landing page shown in the browser after an OAuth redirect.
|
||||||
|
pub fn landing_html(provider_name: &str, success: bool) -> String {
|
||||||
|
let safe_name = html_escape(provider_name);
|
||||||
|
let (icon, heading, subtitle, accent) = if success {
|
||||||
|
(
|
||||||
|
r##"<div style="width:64px;height:64px;border-radius:50%;background:#22c55e;display:flex;align-items:center;justify-content:center;margin:0 auto 24px">
|
||||||
|
<svg width="32" height="32" viewBox="0 0 24 24" fill="none" stroke="#fff" stroke-width="3" stroke-linecap="round" stroke-linejoin="round"><polyline points="20 6 9 17 4 12"/></svg>
|
||||||
|
</div>"##,
|
||||||
|
format!("{} Connected", safe_name),
|
||||||
|
"You can close this window and return to your terminal.",
|
||||||
|
"#22c55e",
|
||||||
|
)
|
||||||
|
} else {
|
||||||
|
(
|
||||||
|
r##"<div style="width:64px;height:64px;border-radius:50%;background:#ef4444;display:flex;align-items:center;justify-content:center;margin:0 auto 24px">
|
||||||
|
<svg width="32" height="32" viewBox="0 0 24 24" fill="none" stroke="#fff" stroke-width="3" stroke-linecap="round" stroke-linejoin="round"><line x1="18" y1="6" x2="6" y2="18"/><line x1="6" y1="6" x2="18" y2="18"/></svg>
|
||||||
|
</div>"##,
|
||||||
|
"Authorization Failed".to_string(),
|
||||||
|
"The request was denied. You can close this window and try again.",
|
||||||
|
"#ef4444",
|
||||||
|
)
|
||||||
|
};
|
||||||
|
|
||||||
|
format!(
|
||||||
|
r#"<!DOCTYPE html>
|
||||||
|
<html lang="en">
|
||||||
|
<head>
|
||||||
|
<meta charset="utf-8">
|
||||||
|
<meta name="viewport" content="width=device-width,initial-scale=1">
|
||||||
|
<title>IronClaw - {heading}</title>
|
||||||
|
<style>
|
||||||
|
* {{ margin:0; padding:0; box-sizing:border-box }}
|
||||||
|
body {{
|
||||||
|
font-family: -apple-system, BlinkMacSystemFont, "Segoe UI", Roboto, Helvetica, Arial, sans-serif;
|
||||||
|
background: #0a0a0a;
|
||||||
|
color: #e5e5e5;
|
||||||
|
display: flex;
|
||||||
|
justify-content: center;
|
||||||
|
align-items: center;
|
||||||
|
min-height: 100vh;
|
||||||
|
}}
|
||||||
|
.card {{
|
||||||
|
text-align: center;
|
||||||
|
padding: 48px 40px;
|
||||||
|
max-width: 420px;
|
||||||
|
border: 1px solid #262626;
|
||||||
|
border-radius: 16px;
|
||||||
|
background: #141414;
|
||||||
|
}}
|
||||||
|
h1 {{
|
||||||
|
font-size: 22px;
|
||||||
|
font-weight: 600;
|
||||||
|
margin-bottom: 8px;
|
||||||
|
color: #fafafa;
|
||||||
|
}}
|
||||||
|
p {{
|
||||||
|
font-size: 14px;
|
||||||
|
color: #a3a3a3;
|
||||||
|
line-height: 1.5;
|
||||||
|
}}
|
||||||
|
.accent {{ color: {accent}; }}
|
||||||
|
.brand {{
|
||||||
|
margin-top: 32px;
|
||||||
|
font-size: 12px;
|
||||||
|
color: #525252;
|
||||||
|
letter-spacing: 0.5px;
|
||||||
|
text-transform: uppercase;
|
||||||
|
}}
|
||||||
|
</style>
|
||||||
|
</head>
|
||||||
|
<body>
|
||||||
|
<div class="card">
|
||||||
|
{icon}
|
||||||
|
<h1>{heading}</h1>
|
||||||
|
<p>{subtitle}</p>
|
||||||
|
<div class="brand">IronClaw</div>
|
||||||
|
</div>
|
||||||
|
</body>
|
||||||
|
</html>"#,
|
||||||
|
heading = heading,
|
||||||
|
icon = icon,
|
||||||
|
subtitle = subtitle,
|
||||||
|
accent = accent,
|
||||||
|
)
|
||||||
|
}
|
||||||
|
|
||||||
|
#[cfg(test)]
|
||||||
|
mod tests {
|
||||||
|
use crate::cli::oauth_defaults::{builtin_credentials, landing_html};
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_unknown_provider_returns_none() {
|
||||||
|
assert!(builtin_credentials("unknown_token").is_none());
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_google_returns_based_on_compile_env() {
|
||||||
|
let creds = builtin_credentials("google_oauth_token");
|
||||||
|
assert!(creds.is_some());
|
||||||
|
let creds = creds.unwrap();
|
||||||
|
assert!(!creds.client_id.is_empty());
|
||||||
|
assert!(!creds.client_secret.is_empty());
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_landing_html_success_contains_key_elements() {
|
||||||
|
let html = landing_html("Google", true);
|
||||||
|
assert!(html.contains("Google Connected"));
|
||||||
|
assert!(html.contains("charset"));
|
||||||
|
assert!(html.contains("IronClaw"));
|
||||||
|
assert!(html.contains("#22c55e")); // green accent
|
||||||
|
assert!(!html.contains("Failed"));
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_landing_html_escapes_provider_name() {
|
||||||
|
let html = landing_html("<script>alert(1)</script>", true);
|
||||||
|
assert!(!html.contains("<script>"));
|
||||||
|
assert!(html.contains("<script>"));
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_landing_html_error_contains_key_elements() {
|
||||||
|
let html = landing_html("Notion", false);
|
||||||
|
assert!(html.contains("Authorization Failed"));
|
||||||
|
assert!(html.contains("charset"));
|
||||||
|
assert!(html.contains("IronClaw"));
|
||||||
|
assert!(html.contains("#ef4444")); // red accent
|
||||||
|
assert!(!html.contains("Connected"));
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,187 @@
|
|||||||
|
//! DM pairing CLI commands.
|
||||||
|
//!
|
||||||
|
//! Manage pairing requests for channels (Telegram, Slack, etc.).
|
||||||
|
|
||||||
|
use clap::Subcommand;
|
||||||
|
|
||||||
|
use crate::pairing::PairingStore;
|
||||||
|
|
||||||
|
/// Pairing subcommands.
|
||||||
|
#[derive(Subcommand, Debug, Clone)]
|
||||||
|
pub enum PairingCommand {
|
||||||
|
/// List pending pairing requests
|
||||||
|
List {
|
||||||
|
/// Channel name (e.g., telegram, slack)
|
||||||
|
#[arg(required = true)]
|
||||||
|
channel: String,
|
||||||
|
|
||||||
|
/// Output as JSON
|
||||||
|
#[arg(long)]
|
||||||
|
json: bool,
|
||||||
|
},
|
||||||
|
|
||||||
|
/// Approve a pairing request by code
|
||||||
|
Approve {
|
||||||
|
/// Channel name (e.g., telegram, slack)
|
||||||
|
#[arg(required = true)]
|
||||||
|
channel: String,
|
||||||
|
|
||||||
|
/// Pairing code (e.g., ABC12345)
|
||||||
|
#[arg(required = true)]
|
||||||
|
code: String,
|
||||||
|
},
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Run pairing CLI command.
|
||||||
|
pub fn run_pairing_command(cmd: PairingCommand) -> Result<(), String> {
|
||||||
|
run_pairing_command_with_store(&PairingStore::new(), cmd)
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Run pairing CLI command with a given store (for testing).
|
||||||
|
pub fn run_pairing_command_with_store(
|
||||||
|
store: &PairingStore,
|
||||||
|
cmd: PairingCommand,
|
||||||
|
) -> Result<(), String> {
|
||||||
|
match cmd {
|
||||||
|
PairingCommand::List { channel, json } => run_list(store, &channel, json),
|
||||||
|
PairingCommand::Approve { channel, code } => run_approve(store, &channel, &code),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
fn run_list(store: &PairingStore, channel: &str, json: bool) -> Result<(), String> {
|
||||||
|
let requests = store.list_pending(channel).map_err(|e| e.to_string())?;
|
||||||
|
|
||||||
|
if json {
|
||||||
|
println!(
|
||||||
|
"{}",
|
||||||
|
serde_json::to_string_pretty(&requests).map_err(|e| e.to_string())?
|
||||||
|
);
|
||||||
|
return Ok(());
|
||||||
|
}
|
||||||
|
|
||||||
|
if requests.is_empty() {
|
||||||
|
println!("No pending {} pairing requests.", channel);
|
||||||
|
return Ok(());
|
||||||
|
}
|
||||||
|
|
||||||
|
println!("Pairing requests ({}):", requests.len());
|
||||||
|
for r in &requests {
|
||||||
|
let meta = r
|
||||||
|
.meta
|
||||||
|
.as_ref()
|
||||||
|
.and_then(|m| m.as_object())
|
||||||
|
.map(|o| {
|
||||||
|
o.iter()
|
||||||
|
.filter_map(|(k, v)| v.as_str().map(|s| format!("{}={}", k, s)))
|
||||||
|
.collect::<Vec<_>>()
|
||||||
|
.join(", ")
|
||||||
|
})
|
||||||
|
.unwrap_or_default();
|
||||||
|
println!(" {} {} {} {}", r.code, r.id, meta, r.created_at);
|
||||||
|
}
|
||||||
|
|
||||||
|
Ok(())
|
||||||
|
}
|
||||||
|
|
||||||
|
fn run_approve(store: &PairingStore, channel: &str, code: &str) -> Result<(), String> {
|
||||||
|
match store.approve(channel, code) {
|
||||||
|
Ok(Some(entry)) => {
|
||||||
|
println!("Approved {} sender {}.", channel, entry.id);
|
||||||
|
Ok(())
|
||||||
|
}
|
||||||
|
Ok(None) => Err(format!(
|
||||||
|
"No pending pairing request found for code: {}",
|
||||||
|
code
|
||||||
|
)),
|
||||||
|
Err(crate::pairing::PairingStoreError::ApproveRateLimited) => Err(
|
||||||
|
"Too many failed approve attempts. Wait a few minutes before trying again.".to_string(),
|
||||||
|
),
|
||||||
|
Err(e) => Err(e.to_string()),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
#[cfg(test)]
|
||||||
|
mod tests {
|
||||||
|
use super::*;
|
||||||
|
use tempfile::TempDir;
|
||||||
|
|
||||||
|
fn test_store() -> (PairingStore, TempDir) {
|
||||||
|
let dir = TempDir::new().unwrap();
|
||||||
|
let store = PairingStore::with_base_dir(dir.path().to_path_buf());
|
||||||
|
(store, dir)
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_list_empty_returns_ok() {
|
||||||
|
let (store, _) = test_store();
|
||||||
|
let result = run_pairing_command_with_store(
|
||||||
|
&store,
|
||||||
|
PairingCommand::List {
|
||||||
|
channel: "telegram".to_string(),
|
||||||
|
json: false,
|
||||||
|
},
|
||||||
|
);
|
||||||
|
assert!(result.is_ok());
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_list_json_empty_returns_ok() {
|
||||||
|
let (store, _) = test_store();
|
||||||
|
let result = run_pairing_command_with_store(
|
||||||
|
&store,
|
||||||
|
PairingCommand::List {
|
||||||
|
channel: "telegram".to_string(),
|
||||||
|
json: true,
|
||||||
|
},
|
||||||
|
);
|
||||||
|
assert!(result.is_ok());
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_approve_invalid_code_returns_err() {
|
||||||
|
let (store, _) = test_store();
|
||||||
|
// Create a pending request so the pairing file exists, then approve with wrong code
|
||||||
|
store.upsert_request("telegram", "user1", None).unwrap();
|
||||||
|
|
||||||
|
let result = run_pairing_command_with_store(
|
||||||
|
&store,
|
||||||
|
PairingCommand::Approve {
|
||||||
|
channel: "telegram".to_string(),
|
||||||
|
code: "BADCODE1".to_string(),
|
||||||
|
},
|
||||||
|
);
|
||||||
|
assert!(result.is_err());
|
||||||
|
assert!(result.unwrap_err().contains("No pending pairing request"));
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_approve_valid_code_returns_ok() {
|
||||||
|
let (store, _) = test_store();
|
||||||
|
let r = store.upsert_request("telegram", "user1", None).unwrap();
|
||||||
|
assert!(r.created);
|
||||||
|
|
||||||
|
let result = run_pairing_command_with_store(
|
||||||
|
&store,
|
||||||
|
PairingCommand::Approve {
|
||||||
|
channel: "telegram".to_string(),
|
||||||
|
code: r.code,
|
||||||
|
},
|
||||||
|
);
|
||||||
|
assert!(result.is_ok());
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_list_with_pending_returns_ok() {
|
||||||
|
let (store, _) = test_store();
|
||||||
|
store.upsert_request("telegram", "user1", None).unwrap();
|
||||||
|
|
||||||
|
let result = run_pairing_command_with_store(
|
||||||
|
&store,
|
||||||
|
PairingCommand::List {
|
||||||
|
channel: "telegram".to_string(),
|
||||||
|
json: false,
|
||||||
|
},
|
||||||
|
);
|
||||||
|
assert!(result.is_ok());
|
||||||
|
}
|
||||||
|
}
|
||||||
+47
-20
@@ -9,7 +9,7 @@ use crate::settings::Settings;
|
|||||||
|
|
||||||
/// Run the status command, printing system health info.
|
/// Run the status command, printing system health info.
|
||||||
pub async fn run_status_command() -> anyhow::Result<()> {
|
pub async fn run_status_command() -> anyhow::Result<()> {
|
||||||
let settings = Settings::load();
|
let settings = Settings::default();
|
||||||
|
|
||||||
println!("IronClaw Status");
|
println!("IronClaw Status");
|
||||||
println!("===============\n");
|
println!("===============\n");
|
||||||
@@ -22,17 +22,37 @@ pub async fn run_status_command() -> anyhow::Result<()> {
|
|||||||
);
|
);
|
||||||
|
|
||||||
// Database
|
// Database
|
||||||
let db_url_set = settings.database_url.is_some() || std::env::var("DATABASE_URL").is_ok();
|
|
||||||
print!(" Database: ");
|
print!(" Database: ");
|
||||||
if db_url_set {
|
let db_backend = std::env::var("DATABASE_BACKEND")
|
||||||
// Try to connect
|
.ok()
|
||||||
|
.unwrap_or_else(|| "postgres".to_string());
|
||||||
|
match db_backend.as_str() {
|
||||||
|
"libsql" | "turso" | "sqlite" => {
|
||||||
|
let path = std::env::var("LIBSQL_PATH")
|
||||||
|
.map(std::path::PathBuf::from)
|
||||||
|
.unwrap_or_else(|_| crate::config::default_libsql_path());
|
||||||
|
if path.exists() {
|
||||||
|
let turso = if std::env::var("LIBSQL_URL").is_ok() {
|
||||||
|
" + Turso sync"
|
||||||
|
} else {
|
||||||
|
""
|
||||||
|
};
|
||||||
|
println!("libSQL ({}{})", path.display(), turso);
|
||||||
|
} else {
|
||||||
|
println!("libSQL (file missing: {})", path.display());
|
||||||
|
}
|
||||||
|
}
|
||||||
|
_ => {
|
||||||
|
if std::env::var("DATABASE_URL").is_ok() {
|
||||||
match check_database().await {
|
match check_database().await {
|
||||||
Ok(()) => println!("connected"),
|
Ok(()) => println!("connected (PostgreSQL)"),
|
||||||
Err(e) => println!("error ({})", e),
|
Err(e) => println!("error ({})", e),
|
||||||
}
|
}
|
||||||
} else {
|
} else {
|
||||||
println!("not configured");
|
println!("not configured");
|
||||||
}
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
// Session / Auth
|
// Session / Auth
|
||||||
print!(" Session: ");
|
print!(" Session: ");
|
||||||
@@ -43,15 +63,17 @@ pub async fn run_status_command() -> anyhow::Result<()> {
|
|||||||
println!("not found (run `ironclaw onboard`)");
|
println!("not found (run `ironclaw onboard`)");
|
||||||
}
|
}
|
||||||
|
|
||||||
// Secrets
|
// Secrets (auto-detect from env only; skip keychain probe to avoid
|
||||||
|
// triggering macOS system password dialogs on a simple status check)
|
||||||
print!(" Secrets: ");
|
print!(" Secrets: ");
|
||||||
let secrets_configured = settings.secrets_master_key_source != crate::settings::KeySource::None
|
if std::env::var("SECRETS_MASTER_KEY").is_ok() {
|
||||||
|| std::env::var("SECRETS_MASTER_KEY").is_ok()
|
println!("configured (env)");
|
||||||
|| crate::secrets::keychain::has_master_key();
|
|
||||||
if secrets_configured {
|
|
||||||
println!("configured ({:?})", settings.secrets_master_key_source);
|
|
||||||
} else {
|
} else {
|
||||||
println!("not configured");
|
// We don't probe the keychain here because get_generic_password()
|
||||||
|
// triggers macOS unlock+authorization dialogs, which is bad UX for
|
||||||
|
// a read-only status command. If onboarding completed with keychain
|
||||||
|
// storage, the key is there; we just can't cheaply verify it.
|
||||||
|
println!("env not set (keychain may be configured)");
|
||||||
}
|
}
|
||||||
|
|
||||||
// Embeddings
|
// Embeddings
|
||||||
@@ -129,19 +151,18 @@ pub async fn run_status_command() -> anyhow::Result<()> {
|
|||||||
Err(_) => println!("none configured"),
|
Err(_) => println!("none configured"),
|
||||||
}
|
}
|
||||||
|
|
||||||
// Settings path
|
// Config path
|
||||||
println!("\n Settings: {}", Settings::default_path().display());
|
println!(
|
||||||
|
"\n Config: {}",
|
||||||
|
crate::bootstrap::ironclaw_env_path().display()
|
||||||
|
);
|
||||||
|
|
||||||
Ok(())
|
Ok(())
|
||||||
}
|
}
|
||||||
|
|
||||||
|
#[cfg(feature = "postgres")]
|
||||||
async fn check_database() -> anyhow::Result<()> {
|
async fn check_database() -> anyhow::Result<()> {
|
||||||
let _ = dotenvy::dotenv();
|
let url = std::env::var("DATABASE_URL").map_err(|_| anyhow::anyhow!("DATABASE_URL not set"))?;
|
||||||
let settings = Settings::load();
|
|
||||||
let url = std::env::var("DATABASE_URL")
|
|
||||||
.ok()
|
|
||||||
.or(settings.database_url)
|
|
||||||
.ok_or_else(|| anyhow::anyhow!("no URL"))?;
|
|
||||||
|
|
||||||
let config: deadpool_postgres::Config = deadpool_postgres::Config {
|
let config: deadpool_postgres::Config = deadpool_postgres::Config {
|
||||||
url: Some(url),
|
url: Some(url),
|
||||||
@@ -167,6 +188,12 @@ async fn check_database() -> anyhow::Result<()> {
|
|||||||
Ok(())
|
Ok(())
|
||||||
}
|
}
|
||||||
|
|
||||||
|
#[cfg(not(feature = "postgres"))]
|
||||||
|
async fn check_database() -> anyhow::Result<()> {
|
||||||
|
// For non-postgres backends, just report configured
|
||||||
|
Ok(())
|
||||||
|
}
|
||||||
|
|
||||||
fn count_wasm_files(dir: &std::path::Path) -> usize {
|
fn count_wasm_files(dir: &std::path::Path) -> usize {
|
||||||
std::fs::read_dir(dir)
|
std::fs::read_dir(dir)
|
||||||
.map(|entries| {
|
.map(|entries| {
|
||||||
|
|||||||
+199
-127
@@ -11,8 +11,11 @@ use clap::Subcommand;
|
|||||||
use tokio::fs;
|
use tokio::fs;
|
||||||
|
|
||||||
use crate::config::Config;
|
use crate::config::Config;
|
||||||
use crate::history::Store;
|
#[allow(unused_imports)]
|
||||||
use crate::secrets::{CreateSecretParams, PostgresSecretsStore, SecretsCrypto, SecretsStore};
|
use crate::db::Database;
|
||||||
|
#[cfg(feature = "postgres")]
|
||||||
|
use crate::secrets::PostgresSecretsStore;
|
||||||
|
use crate::secrets::{CreateSecretParams, SecretsCrypto, SecretsStore};
|
||||||
use crate::tools::wasm::{CapabilitiesFile, compute_binary_hash};
|
use crate::tools::wasm::{CapabilitiesFile, compute_binary_hash};
|
||||||
|
|
||||||
/// Default tools directory.
|
/// Default tools directory.
|
||||||
@@ -420,13 +423,13 @@ async fn extract_crate_name(cargo_toml: &Path) -> anyhow::Result<String> {
|
|||||||
// Simple TOML parsing for [package] name
|
// Simple TOML parsing for [package] name
|
||||||
for line in content.lines() {
|
for line in content.lines() {
|
||||||
let line = line.trim();
|
let line = line.trim();
|
||||||
if line.starts_with("name") {
|
if line.starts_with("name")
|
||||||
if let Some((_, value)) = line.split_once('=') {
|
&& let Some((_, value)) = line.split_once('=')
|
||||||
|
{
|
||||||
let name = value.trim().trim_matches('"').trim_matches('\'');
|
let name = value.trim().trim_matches('"').trim_matches('\'');
|
||||||
return Ok(name.to_string());
|
return Ok(name.to_string());
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
|
||||||
|
|
||||||
anyhow::bail!(
|
anyhow::bail!(
|
||||||
"Could not extract package name from {}",
|
"Could not extract package name from {}",
|
||||||
@@ -488,12 +491,12 @@ async fn list_tools(dir: Option<PathBuf>, verbose: bool) -> anyhow::Result<()> {
|
|||||||
|
|
||||||
if has_caps {
|
if has_caps {
|
||||||
let caps_path = path.with_extension("capabilities.json");
|
let caps_path = path.with_extension("capabilities.json");
|
||||||
if let Ok(content) = fs::read_to_string(&caps_path).await {
|
if let Ok(content) = fs::read_to_string(&caps_path).await
|
||||||
if let Ok(caps) = CapabilitiesFile::from_json(&content) {
|
&& let Ok(caps) = CapabilitiesFile::from_json(&content)
|
||||||
|
{
|
||||||
print_capabilities_summary(&caps);
|
print_capabilities_summary(&caps);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
|
||||||
println!();
|
println!();
|
||||||
} else {
|
} else {
|
||||||
let caps_indicator = if has_caps { "✓" } else { "✗" };
|
let caps_indicator = if has_caps { "✓" } else { "✗" };
|
||||||
@@ -604,17 +607,17 @@ fn print_capabilities_summary(caps: &CapabilitiesFile) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
if let Some(ref secrets) = caps.secrets {
|
if let Some(ref secrets) = caps.secrets
|
||||||
if !secrets.allowed_names.is_empty() {
|
&& !secrets.allowed_names.is_empty()
|
||||||
|
{
|
||||||
parts.push(format!("secrets: {}", secrets.allowed_names.len()));
|
parts.push(format!("secrets: {}", secrets.allowed_names.len()));
|
||||||
}
|
}
|
||||||
}
|
|
||||||
|
|
||||||
if let Some(ref ws) = caps.workspace {
|
if let Some(ref ws) = caps.workspace
|
||||||
if !ws.allowed_prefixes.is_empty() {
|
&& !ws.allowed_prefixes.is_empty()
|
||||||
|
{
|
||||||
parts.push("workspace: read".to_string());
|
parts.push("workspace: read".to_string());
|
||||||
}
|
}
|
||||||
}
|
|
||||||
|
|
||||||
if !parts.is_empty() {
|
if !parts.is_empty() {
|
||||||
println!(" Perms: {}", parts.join(", "));
|
println!(" Perms: {}", parts.join(", "));
|
||||||
@@ -650,33 +653,33 @@ fn print_capabilities_detail(caps: &CapabilitiesFile) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
if let Some(ref secrets) = caps.secrets {
|
if let Some(ref secrets) = caps.secrets
|
||||||
if !secrets.allowed_names.is_empty() {
|
&& !secrets.allowed_names.is_empty()
|
||||||
|
{
|
||||||
println!(" Secrets (existence check only):");
|
println!(" Secrets (existence check only):");
|
||||||
for name in &secrets.allowed_names {
|
for name in &secrets.allowed_names {
|
||||||
println!(" {}", name);
|
println!(" {}", name);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
|
||||||
|
|
||||||
if let Some(ref tool_invoke) = caps.tool_invoke {
|
if let Some(ref tool_invoke) = caps.tool_invoke
|
||||||
if !tool_invoke.aliases.is_empty() {
|
&& !tool_invoke.aliases.is_empty()
|
||||||
|
{
|
||||||
println!(" Tool aliases:");
|
println!(" Tool aliases:");
|
||||||
for (alias, real_name) in &tool_invoke.aliases {
|
for (alias, real_name) in &tool_invoke.aliases {
|
||||||
println!(" {} -> {}", alias, real_name);
|
println!(" {} -> {}", alias, real_name);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
|
||||||
|
|
||||||
if let Some(ref ws) = caps.workspace {
|
if let Some(ref ws) = caps.workspace
|
||||||
if !ws.allowed_prefixes.is_empty() {
|
&& !ws.allowed_prefixes.is_empty()
|
||||||
|
{
|
||||||
println!(" Workspace read prefixes:");
|
println!(" Workspace read prefixes:");
|
||||||
for prefix in &ws.allowed_prefixes {
|
for prefix in &ws.allowed_prefixes {
|
||||||
println!(" {}", prefix);
|
println!(" {}", prefix);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
|
||||||
|
|
||||||
/// Configure authentication for a tool.
|
/// Configure authentication for a tool.
|
||||||
async fn auth_tool(name: String, dir: Option<PathBuf>, user_id: String) -> anyhow::Result<()> {
|
async fn auth_tool(name: String, dir: Option<PathBuf>, user_id: String) -> anyhow::Result<()> {
|
||||||
@@ -715,18 +718,65 @@ async fn auth_tool(name: String, dir: Option<PathBuf>, user_id: String) -> anyho
|
|||||||
println!();
|
println!();
|
||||||
|
|
||||||
// Initialize secrets store
|
// Initialize secrets store
|
||||||
let config = Config::from_env()?;
|
let config = Config::from_env().await?;
|
||||||
let master_key = config.secrets.master_key().ok_or_else(|| {
|
let master_key = config.secrets.master_key().ok_or_else(|| {
|
||||||
anyhow::anyhow!(
|
anyhow::anyhow!(
|
||||||
"SECRETS_MASTER_KEY not set. Run 'ironclaw onboard' first or set it in .env"
|
"SECRETS_MASTER_KEY not set. Run 'ironclaw onboard' first or set it in .env"
|
||||||
)
|
)
|
||||||
})?;
|
})?;
|
||||||
|
|
||||||
let store = Store::new(&config.database).await?;
|
|
||||||
store.run_migrations().await?;
|
|
||||||
|
|
||||||
let crypto = SecretsCrypto::new(master_key.clone())?;
|
let crypto = SecretsCrypto::new(master_key.clone())?;
|
||||||
let secrets_store = Arc::new(PostgresSecretsStore::new(store.pool(), Arc::new(crypto)));
|
|
||||||
|
let secrets_store: Arc<dyn SecretsStore + Send + Sync> = {
|
||||||
|
#[cfg(feature = "postgres")]
|
||||||
|
{
|
||||||
|
let store = crate::history::Store::new(&config.database).await?;
|
||||||
|
store.run_migrations().await?;
|
||||||
|
Arc::new(PostgresSecretsStore::new(store.pool(), Arc::new(crypto)))
|
||||||
|
}
|
||||||
|
#[cfg(all(feature = "libsql", not(feature = "postgres")))]
|
||||||
|
{
|
||||||
|
use crate::db::Database as _;
|
||||||
|
use crate::db::libsql_backend::LibSqlBackend;
|
||||||
|
use secrecy::ExposeSecret as _;
|
||||||
|
|
||||||
|
let default_path = crate::config::default_libsql_path();
|
||||||
|
let db_path = config
|
||||||
|
.database
|
||||||
|
.libsql_path
|
||||||
|
.as_deref()
|
||||||
|
.unwrap_or(&default_path);
|
||||||
|
|
||||||
|
let backend = if let Some(ref url) = config.database.libsql_url {
|
||||||
|
let token = config.database.libsql_auth_token.as_ref().ok_or_else(|| {
|
||||||
|
anyhow::anyhow!("LIBSQL_AUTH_TOKEN is required when LIBSQL_URL is set")
|
||||||
|
})?;
|
||||||
|
LibSqlBackend::new_remote_replica(db_path, url, token.expose_secret())
|
||||||
|
.await
|
||||||
|
.map_err(|e| anyhow::anyhow!("{}", e))?
|
||||||
|
} else {
|
||||||
|
LibSqlBackend::new_local(db_path)
|
||||||
|
.await
|
||||||
|
.map_err(|e| anyhow::anyhow!("{}", e))?
|
||||||
|
};
|
||||||
|
backend
|
||||||
|
.run_migrations()
|
||||||
|
.await
|
||||||
|
.map_err(|e| anyhow::anyhow!("{}", e))?;
|
||||||
|
|
||||||
|
Arc::new(crate::secrets::LibSqlSecretsStore::new(
|
||||||
|
backend.shared_db(),
|
||||||
|
Arc::new(crypto),
|
||||||
|
))
|
||||||
|
}
|
||||||
|
#[cfg(not(any(feature = "postgres", feature = "libsql")))]
|
||||||
|
{
|
||||||
|
let _ = crypto;
|
||||||
|
anyhow::bail!(
|
||||||
|
"No database backend available for secrets. Enable 'postgres' or 'libsql' feature."
|
||||||
|
);
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
// Check if already configured
|
// Check if already configured
|
||||||
let already_configured = secrets_store
|
let already_configured = secrets_store
|
||||||
@@ -752,9 +802,10 @@ async fn auth_tool(name: String, dir: Option<PathBuf>, user_id: String) -> anyho
|
|||||||
}
|
}
|
||||||
|
|
||||||
// Check for environment variable
|
// Check for environment variable
|
||||||
if let Some(ref env_var) = auth.env_var {
|
if let Some(ref env_var) = auth.env_var
|
||||||
if let Ok(token) = std::env::var(env_var) {
|
&& let Ok(token) = std::env::var(env_var)
|
||||||
if !token.is_empty() {
|
&& !token.is_empty()
|
||||||
|
{
|
||||||
println!(" Found {} in environment.", env_var);
|
println!(" Found {} in environment.", env_var);
|
||||||
println!();
|
println!();
|
||||||
|
|
||||||
@@ -772,31 +823,82 @@ async fn auth_tool(name: String, dir: Option<PathBuf>, user_id: String) -> anyho
|
|||||||
println!(" Validation failed: {}", e);
|
println!(" Validation failed: {}", e);
|
||||||
println!();
|
println!();
|
||||||
println!(" Falling back to manual entry...");
|
println!(" Falling back to manual entry...");
|
||||||
return auth_tool_manual(&secrets_store, &user_id, &auth).await;
|
return auth_tool_manual(secrets_store.as_ref(), &user_id, &auth).await;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// Save the token
|
// Save the token
|
||||||
save_token(&secrets_store, &user_id, &auth, &token).await?;
|
save_token(secrets_store.as_ref(), &user_id, &auth, &token, None, None).await?;
|
||||||
print_success(display_name);
|
print_success(display_name);
|
||||||
return Ok(());
|
return Ok(());
|
||||||
}
|
}
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// Check for OAuth configuration
|
// Check for OAuth configuration
|
||||||
if let Some(ref oauth) = auth.oauth {
|
if let Some(ref oauth) = auth.oauth {
|
||||||
return auth_tool_oauth(&secrets_store, &user_id, &auth, oauth).await;
|
// For providers with shared tokens (e.g., all Google tools share google_oauth_token),
|
||||||
|
// combine scopes from all installed tools so one auth covers everything.
|
||||||
|
let combined = combine_provider_scopes(&tools_dir, &auth.secret_name, oauth).await;
|
||||||
|
if combined.scopes.len() > oauth.scopes.len() {
|
||||||
|
let extra = combined.scopes.len() - oauth.scopes.len();
|
||||||
|
println!(
|
||||||
|
" Including scopes from {} other installed tool(s) sharing this credential.",
|
||||||
|
extra
|
||||||
|
);
|
||||||
|
println!();
|
||||||
|
}
|
||||||
|
return auth_tool_oauth(secrets_store.as_ref(), &user_id, &auth, &combined).await;
|
||||||
}
|
}
|
||||||
|
|
||||||
// Fall back to manual entry
|
// Fall back to manual entry
|
||||||
auth_tool_manual(&secrets_store, &user_id, &auth).await
|
auth_tool_manual(secrets_store.as_ref(), &user_id, &auth).await
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Scan the tools directory for all capabilities files sharing the same secret_name
|
||||||
|
/// and combine their OAuth scopes. This way, authing any Google tool requests scopes
|
||||||
|
/// for ALL installed Google tools, so one login covers everything.
|
||||||
|
async fn combine_provider_scopes(
|
||||||
|
tools_dir: &Path,
|
||||||
|
secret_name: &str,
|
||||||
|
base_oauth: &crate::tools::wasm::OAuthConfigSchema,
|
||||||
|
) -> crate::tools::wasm::OAuthConfigSchema {
|
||||||
|
let mut all_scopes: std::collections::HashSet<String> =
|
||||||
|
base_oauth.scopes.iter().cloned().collect();
|
||||||
|
|
||||||
|
if let Ok(mut entries) = tokio::fs::read_dir(tools_dir).await {
|
||||||
|
while let Ok(Some(entry)) = entries.next_entry().await {
|
||||||
|
let path = entry.path();
|
||||||
|
if path.extension().and_then(|e| e.to_str()) != Some("json") {
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
let name = path
|
||||||
|
.file_name()
|
||||||
|
.and_then(|n| n.to_str())
|
||||||
|
.unwrap_or_default();
|
||||||
|
if !name.ends_with(".capabilities.json") {
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
|
||||||
|
if let Ok(content) = tokio::fs::read_to_string(&path).await
|
||||||
|
&& let Ok(caps) = CapabilitiesFile::from_json(&content)
|
||||||
|
&& let Some(auth) = &caps.auth
|
||||||
|
&& auth.secret_name == secret_name
|
||||||
|
&& let Some(oauth) = &auth.oauth
|
||||||
|
{
|
||||||
|
all_scopes.extend(oauth.scopes.iter().cloned());
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
let mut combined = base_oauth.clone();
|
||||||
|
combined.scopes = all_scopes.into_iter().collect();
|
||||||
|
combined.scopes.sort(); // deterministic ordering
|
||||||
|
combined
|
||||||
}
|
}
|
||||||
|
|
||||||
/// OAuth browser-based login flow.
|
/// OAuth browser-based login flow.
|
||||||
async fn auth_tool_oauth(
|
async fn auth_tool_oauth(
|
||||||
store: &PostgresSecretsStore,
|
store: &(dyn SecretsStore + Send + Sync),
|
||||||
user_id: &str,
|
user_id: &str,
|
||||||
auth: &crate::tools::wasm::AuthCapabilitySchema,
|
auth: &crate::tools::wasm::AuthCapabilitySchema,
|
||||||
oauth: &crate::tools::wasm::OAuthConfigSchema,
|
oauth: &crate::tools::wasm::OAuthConfigSchema,
|
||||||
@@ -804,12 +906,14 @@ async fn auth_tool_oauth(
|
|||||||
use base64::{Engine, engine::general_purpose::URL_SAFE_NO_PAD};
|
use base64::{Engine, engine::general_purpose::URL_SAFE_NO_PAD};
|
||||||
use rand::RngCore;
|
use rand::RngCore;
|
||||||
use sha2::{Digest, Sha256};
|
use sha2::{Digest, Sha256};
|
||||||
use tokio::io::{AsyncBufReadExt, AsyncWriteExt, BufReader};
|
|
||||||
use tokio::net::TcpListener;
|
use crate::cli::oauth_defaults::{self, OAUTH_CALLBACK_PORT};
|
||||||
|
|
||||||
let display_name = auth.display_name.as_deref().unwrap_or(&auth.secret_name);
|
let display_name = auth.display_name.as_deref().unwrap_or(&auth.secret_name);
|
||||||
|
|
||||||
// Get client_id from config or env
|
// Get client_id: capabilities file > runtime env var > built-in defaults
|
||||||
|
let builtin = oauth_defaults::builtin_credentials(&auth.secret_name);
|
||||||
|
|
||||||
let client_id = oauth
|
let client_id = oauth
|
||||||
.client_id
|
.client_id
|
||||||
.clone()
|
.clone()
|
||||||
@@ -819,41 +923,32 @@ async fn auth_tool_oauth(
|
|||||||
.as_ref()
|
.as_ref()
|
||||||
.and_then(|env| std::env::var(env).ok())
|
.and_then(|env| std::env::var(env).ok())
|
||||||
})
|
})
|
||||||
|
.or_else(|| builtin.as_ref().map(|c| c.client_id.to_string()))
|
||||||
.ok_or_else(|| {
|
.ok_or_else(|| {
|
||||||
anyhow::anyhow!(
|
anyhow::anyhow!(
|
||||||
"OAuth client_id not configured.\n\
|
"OAuth client_id not configured.\n\
|
||||||
Set it in the capabilities file or via environment variable."
|
Set {} env var, or build with IRONCLAW_GOOGLE_CLIENT_ID.",
|
||||||
|
oauth.client_id_env.as_deref().unwrap_or("the client_id")
|
||||||
)
|
)
|
||||||
})?;
|
})?;
|
||||||
|
|
||||||
// Get client_secret if provided
|
// Get client_secret: capabilities file > runtime env var > built-in defaults
|
||||||
let client_secret = oauth.client_secret.clone().or_else(|| {
|
let client_secret = oauth
|
||||||
|
.client_secret
|
||||||
|
.clone()
|
||||||
|
.or_else(|| {
|
||||||
oauth
|
oauth
|
||||||
.client_secret_env
|
.client_secret_env
|
||||||
.as_ref()
|
.as_ref()
|
||||||
.and_then(|env| std::env::var(env).ok())
|
.and_then(|env| std::env::var(env).ok())
|
||||||
});
|
})
|
||||||
|
.or_else(|| builtin.as_ref().map(|c| c.client_secret.to_string()));
|
||||||
|
|
||||||
println!(" Starting OAuth authentication...");
|
println!(" Starting OAuth authentication...");
|
||||||
println!();
|
println!();
|
||||||
|
|
||||||
// Find an available port for the callback
|
let listener = oauth_defaults::bind_callback_listener().await?;
|
||||||
let mut listener = None;
|
let redirect_uri = format!("http://localhost:{}/callback", OAUTH_CALLBACK_PORT);
|
||||||
let mut port = 0;
|
|
||||||
|
|
||||||
for p in 9876..=9886 {
|
|
||||||
match TcpListener::bind(format!("127.0.0.1:{}", p)).await {
|
|
||||||
Ok(l) => {
|
|
||||||
listener = Some(l);
|
|
||||||
port = p;
|
|
||||||
break;
|
|
||||||
}
|
|
||||||
Err(_) => continue,
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
let listener = listener.ok_or_else(|| anyhow::anyhow!("Could not find available port"))?;
|
|
||||||
let redirect_uri = format!("http://localhost:{}/callback", port);
|
|
||||||
|
|
||||||
// Generate PKCE verifier and challenge
|
// Generate PKCE verifier and challenge
|
||||||
let (code_verifier, code_challenge) = if oauth.use_pkce {
|
let (code_verifier, code_challenge) = if oauth.use_pkce {
|
||||||
@@ -912,65 +1007,8 @@ async fn auth_tool_oauth(
|
|||||||
|
|
||||||
println!(" Waiting for authorization...");
|
println!(" Waiting for authorization...");
|
||||||
|
|
||||||
// Wait for callback with timeout
|
let code =
|
||||||
let timeout = std::time::Duration::from_secs(300);
|
oauth_defaults::wait_for_callback(listener, "/callback", "code", display_name).await?;
|
||||||
let code = tokio::time::timeout(timeout, async {
|
|
||||||
loop {
|
|
||||||
let (mut socket, _) = listener.accept().await?;
|
|
||||||
|
|
||||||
let mut reader = BufReader::new(&mut socket);
|
|
||||||
let mut request_line = String::new();
|
|
||||||
reader.read_line(&mut request_line).await?;
|
|
||||||
|
|
||||||
// Parse GET /callback?code=xxx HTTP/1.1
|
|
||||||
if let Some(path) = request_line.split_whitespace().nth(1) {
|
|
||||||
if path.starts_with("/callback") {
|
|
||||||
if let Some(query) = path.split('?').nth(1) {
|
|
||||||
for param in query.split('&') {
|
|
||||||
let parts: Vec<&str> = param.splitn(2, '=').collect();
|
|
||||||
if parts.len() == 2 && parts[0] == "code" {
|
|
||||||
let code = urlencoding::decode(parts[1])
|
|
||||||
.unwrap_or_else(|_| parts[1].into())
|
|
||||||
.into_owned();
|
|
||||||
|
|
||||||
// Send success response
|
|
||||||
let response = format!(
|
|
||||||
"HTTP/1.1 200 OK\r\n\
|
|
||||||
Content-Type: text/html\r\n\
|
|
||||||
\r\n\
|
|
||||||
<!DOCTYPE html><html><body style=\"font-family: sans-serif; \
|
|
||||||
display: flex; justify-content: center; align-items: center; \
|
|
||||||
height: 100vh; margin: 0; background: #191919; color: white;\">\
|
|
||||||
<div style=\"text-align: center;\">\
|
|
||||||
<h1>✓ {} Connected!</h1>\
|
|
||||||
<p>You can close this window.</p>\
|
|
||||||
</div></body></html>",
|
|
||||||
display_name
|
|
||||||
);
|
|
||||||
let _ = socket.write_all(response.as_bytes()).await;
|
|
||||||
let _ = socket.shutdown().await;
|
|
||||||
|
|
||||||
return Ok::<_, anyhow::Error>(code);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// Check for error
|
|
||||||
if query.contains("error=") {
|
|
||||||
let response =
|
|
||||||
"HTTP/1.1 400 Bad Request\r\n\r\nAuthorization denied";
|
|
||||||
let _ = socket.write_all(response.as_bytes()).await;
|
|
||||||
return Err(anyhow::anyhow!("Authorization denied by user"));
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
let response = "HTTP/1.1 404 Not Found\r\n\r\n";
|
|
||||||
let _ = socket.write_all(response.as_bytes()).await;
|
|
||||||
}
|
|
||||||
})
|
|
||||||
.await
|
|
||||||
.map_err(|_| anyhow::anyhow!("Timed out waiting for authorization"))??;
|
|
||||||
|
|
||||||
println!();
|
println!();
|
||||||
println!(" Exchanging code for token...");
|
println!(" Exchanging code for token...");
|
||||||
@@ -1021,8 +1059,19 @@ async fn auth_tool_oauth(
|
|||||||
)
|
)
|
||||||
})?;
|
})?;
|
||||||
|
|
||||||
// Save the token
|
let refresh_token = token_data.get("refresh_token").and_then(|v| v.as_str());
|
||||||
save_token(store, user_id, auth, access_token).await?;
|
let expires_in = token_data.get("expires_in").and_then(|v| v.as_u64());
|
||||||
|
|
||||||
|
// Save the token (with refresh token and expiry if provided)
|
||||||
|
save_token(
|
||||||
|
store,
|
||||||
|
user_id,
|
||||||
|
auth,
|
||||||
|
access_token,
|
||||||
|
refresh_token,
|
||||||
|
expires_in,
|
||||||
|
)
|
||||||
|
.await?;
|
||||||
|
|
||||||
// Extract any additional info for display
|
// Extract any additional info for display
|
||||||
let workspace_name = token_data
|
let workspace_name = token_data
|
||||||
@@ -1044,7 +1093,7 @@ async fn auth_tool_oauth(
|
|||||||
|
|
||||||
/// Manual token entry flow.
|
/// Manual token entry flow.
|
||||||
async fn auth_tool_manual(
|
async fn auth_tool_manual(
|
||||||
store: &PostgresSecretsStore,
|
store: &(dyn SecretsStore + Send + Sync),
|
||||||
user_id: &str,
|
user_id: &str,
|
||||||
auth: &crate::tools::wasm::AuthCapabilitySchema,
|
auth: &crate::tools::wasm::AuthCapabilitySchema,
|
||||||
) -> anyhow::Result<()> {
|
) -> anyhow::Result<()> {
|
||||||
@@ -1124,8 +1173,8 @@ async fn auth_tool_manual(
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// Save the token
|
// Save the token (manual path: no refresh token or expiry)
|
||||||
save_token(store, user_id, auth, &token).await?;
|
save_token(store, user_id, auth, &token, None, None).await?;
|
||||||
print_success(display_name);
|
print_success(display_name);
|
||||||
Ok(())
|
Ok(())
|
||||||
}
|
}
|
||||||
@@ -1216,11 +1265,16 @@ async fn validate_token(
|
|||||||
}
|
}
|
||||||
|
|
||||||
/// Save token to secrets store.
|
/// Save token to secrets store.
|
||||||
|
///
|
||||||
|
/// Optionally stores a refresh token (as `{secret_name}_refresh_token`) and
|
||||||
|
/// sets `expires_at` on the access token so the runtime can auto-refresh.
|
||||||
async fn save_token(
|
async fn save_token(
|
||||||
store: &PostgresSecretsStore,
|
store: &(dyn SecretsStore + Send + Sync),
|
||||||
user_id: &str,
|
user_id: &str,
|
||||||
auth: &crate::tools::wasm::AuthCapabilitySchema,
|
auth: &crate::tools::wasm::AuthCapabilitySchema,
|
||||||
token: &str,
|
token: &str,
|
||||||
|
refresh_token: Option<&str>,
|
||||||
|
expires_in: Option<u64>,
|
||||||
) -> anyhow::Result<()> {
|
) -> anyhow::Result<()> {
|
||||||
let mut params = CreateSecretParams::new(&auth.secret_name, token);
|
let mut params = CreateSecretParams::new(&auth.secret_name, token);
|
||||||
|
|
||||||
@@ -1228,11 +1282,29 @@ async fn save_token(
|
|||||||
params = params.with_provider(provider);
|
params = params.with_provider(provider);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if let Some(secs) = expires_in {
|
||||||
|
let expires_at = chrono::Utc::now() + chrono::Duration::seconds(secs as i64);
|
||||||
|
params = params.with_expiry(expires_at);
|
||||||
|
}
|
||||||
|
|
||||||
store
|
store
|
||||||
.create(user_id, params)
|
.create(user_id, params)
|
||||||
.await
|
.await
|
||||||
.map_err(|e| anyhow::anyhow!("Failed to save token: {}", e))?;
|
.map_err(|e| anyhow::anyhow!("Failed to save token: {}", e))?;
|
||||||
|
|
||||||
|
// Store refresh token separately (no expiry, it's long-lived)
|
||||||
|
if let Some(rt) = refresh_token {
|
||||||
|
let refresh_name = format!("{}_refresh_token", auth.secret_name);
|
||||||
|
let mut refresh_params = CreateSecretParams::new(&refresh_name, rt);
|
||||||
|
if let Some(ref provider) = auth.provider {
|
||||||
|
refresh_params = refresh_params.with_provider(provider);
|
||||||
|
}
|
||||||
|
store
|
||||||
|
.create(user_id, refresh_params)
|
||||||
|
.await
|
||||||
|
.map_err(|e| anyhow::anyhow!("Failed to save refresh token: {}", e))?;
|
||||||
|
}
|
||||||
|
|
||||||
Ok(())
|
Ok(())
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
+619
-150
File diff suppressed because it is too large
Load Diff
@@ -45,20 +45,21 @@ impl ContextManager {
|
|||||||
title: impl Into<String>,
|
title: impl Into<String>,
|
||||||
description: impl Into<String>,
|
description: impl Into<String>,
|
||||||
) -> Result<Uuid, JobError> {
|
) -> Result<Uuid, JobError> {
|
||||||
let contexts = self.contexts.read().await;
|
// Hold write lock for the entire check-insert to prevent TOCTOU races
|
||||||
|
// where two concurrent calls both pass the active_count check.
|
||||||
|
let mut contexts = self.contexts.write().await;
|
||||||
let active_count = contexts.values().filter(|c| c.state.is_active()).count();
|
let active_count = contexts.values().filter(|c| c.state.is_active()).count();
|
||||||
|
|
||||||
if active_count >= self.max_jobs {
|
if active_count >= self.max_jobs {
|
||||||
return Err(JobError::MaxJobsExceeded { max: self.max_jobs });
|
return Err(JobError::MaxJobsExceeded { max: self.max_jobs });
|
||||||
}
|
}
|
||||||
drop(contexts);
|
|
||||||
|
|
||||||
let context = JobContext::with_user(user_id, title, description);
|
let context = JobContext::with_user(user_id, title, description);
|
||||||
let job_id = context.job_id;
|
let job_id = context.job_id;
|
||||||
|
contexts.insert(job_id, context);
|
||||||
|
drop(contexts);
|
||||||
|
|
||||||
let memory = Memory::new(job_id);
|
let memory = Memory::new(job_id);
|
||||||
|
|
||||||
self.contexts.write().await.insert(job_id, context);
|
|
||||||
self.memories.write().await.insert(job_id, memory);
|
self.memories.write().await.insert(job_id, memory);
|
||||||
|
|
||||||
Ok(job_id)
|
Ok(job_id)
|
||||||
|
|||||||
@@ -119,6 +119,10 @@ pub struct JobContext {
|
|||||||
pub estimated_duration: Option<Duration>,
|
pub estimated_duration: Option<Duration>,
|
||||||
/// Actual cost so far.
|
/// Actual cost so far.
|
||||||
pub actual_cost: Decimal,
|
pub actual_cost: Decimal,
|
||||||
|
/// Total tokens consumed by LLM calls in this job.
|
||||||
|
pub total_tokens_used: u64,
|
||||||
|
/// Maximum tokens allowed per job (0 = unlimited).
|
||||||
|
pub max_tokens: u64,
|
||||||
/// When the job was created.
|
/// When the job was created.
|
||||||
pub created_at: DateTime<Utc>,
|
pub created_at: DateTime<Utc>,
|
||||||
/// When the job was started.
|
/// When the job was started.
|
||||||
@@ -159,6 +163,8 @@ impl JobContext {
|
|||||||
estimated_cost: None,
|
estimated_cost: None,
|
||||||
estimated_duration: None,
|
estimated_duration: None,
|
||||||
actual_cost: Decimal::ZERO,
|
actual_cost: Decimal::ZERO,
|
||||||
|
total_tokens_used: 0,
|
||||||
|
max_tokens: 0,
|
||||||
created_at: Utc::now(),
|
created_at: Utc::now(),
|
||||||
started_at: None,
|
started_at: None,
|
||||||
completed_at: None,
|
completed_at: None,
|
||||||
@@ -189,6 +195,14 @@ impl JobContext {
|
|||||||
};
|
};
|
||||||
|
|
||||||
self.transitions.push(transition);
|
self.transitions.push(transition);
|
||||||
|
|
||||||
|
// Cap transition history to prevent unbounded memory growth
|
||||||
|
const MAX_TRANSITIONS: usize = 200;
|
||||||
|
if self.transitions.len() > MAX_TRANSITIONS {
|
||||||
|
let drain_count = self.transitions.len() - MAX_TRANSITIONS;
|
||||||
|
self.transitions.drain(..drain_count);
|
||||||
|
}
|
||||||
|
|
||||||
self.state = new_state;
|
self.state = new_state;
|
||||||
|
|
||||||
// Update timestamps
|
// Update timestamps
|
||||||
@@ -210,6 +224,29 @@ impl JobContext {
|
|||||||
self.actual_cost += cost;
|
self.actual_cost += cost;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/// Record token usage from an LLM call. Returns an error string if the
|
||||||
|
/// token budget has been exceeded after this addition.
|
||||||
|
pub fn add_tokens(&mut self, tokens: u64) -> Result<(), String> {
|
||||||
|
self.total_tokens_used += tokens;
|
||||||
|
if self.max_tokens > 0 && self.total_tokens_used > self.max_tokens {
|
||||||
|
Err(format!(
|
||||||
|
"Token budget exceeded: used {} of {} allowed tokens",
|
||||||
|
self.total_tokens_used, self.max_tokens
|
||||||
|
))
|
||||||
|
} else {
|
||||||
|
Ok(())
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Check whether the monetary budget has been exceeded.
|
||||||
|
pub fn budget_exceeded(&self) -> bool {
|
||||||
|
if let Some(ref budget) = self.budget {
|
||||||
|
self.actual_cost > *budget
|
||||||
|
} else {
|
||||||
|
false
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
/// Get the duration since the job started.
|
/// Get the duration since the job started.
|
||||||
pub fn elapsed(&self) -> Option<Duration> {
|
pub fn elapsed(&self) -> Option<Duration> {
|
||||||
self.started_at.map(|start| {
|
self.started_at.map(|start| {
|
||||||
@@ -274,6 +311,57 @@ mod tests {
|
|||||||
assert_eq!(ctx.state, JobState::Completed);
|
assert_eq!(ctx.state, JobState::Completed);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_transition_history_capped() {
|
||||||
|
let mut ctx = JobContext::new("Test", "Transition cap test");
|
||||||
|
// Cycle through Pending -> InProgress -> Stuck -> InProgress -> Stuck ...
|
||||||
|
ctx.transition_to(JobState::InProgress, None).unwrap();
|
||||||
|
for i in 0..250 {
|
||||||
|
ctx.mark_stuck(format!("stuck {}", i)).unwrap();
|
||||||
|
ctx.attempt_recovery().unwrap();
|
||||||
|
}
|
||||||
|
// 1 initial + 250*2 = 501 transitions, should be capped at 200
|
||||||
|
assert!(
|
||||||
|
ctx.transitions.len() <= 200,
|
||||||
|
"transitions should be capped at 200, got {}",
|
||||||
|
ctx.transitions.len()
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_add_tokens_enforces_budget() {
|
||||||
|
let mut ctx = JobContext::new("Test", "Budget test");
|
||||||
|
ctx.max_tokens = 1000;
|
||||||
|
assert!(ctx.add_tokens(500).is_ok());
|
||||||
|
assert_eq!(ctx.total_tokens_used, 500);
|
||||||
|
assert!(ctx.add_tokens(600).is_err());
|
||||||
|
assert_eq!(ctx.total_tokens_used, 1100); // tokens still recorded
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_add_tokens_unlimited() {
|
||||||
|
let mut ctx = JobContext::new("Test", "No budget");
|
||||||
|
// max_tokens = 0 means unlimited
|
||||||
|
assert!(ctx.add_tokens(1_000_000).is_ok());
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_budget_exceeded() {
|
||||||
|
let mut ctx = JobContext::new("Test", "Money test");
|
||||||
|
ctx.budget = Some(Decimal::new(100, 0)); // $100
|
||||||
|
assert!(!ctx.budget_exceeded());
|
||||||
|
ctx.add_cost(Decimal::new(50, 0));
|
||||||
|
assert!(!ctx.budget_exceeded());
|
||||||
|
ctx.add_cost(Decimal::new(60, 0));
|
||||||
|
assert!(ctx.budget_exceeded());
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_budget_exceeded_none() {
|
||||||
|
let ctx = JobContext::new("Test", "No budget");
|
||||||
|
assert!(!ctx.budget_exceeded()); // No budget = never exceeded
|
||||||
|
}
|
||||||
|
|
||||||
#[test]
|
#[test]
|
||||||
fn test_stuck_recovery() {
|
fn test_stuck_recovery() {
|
||||||
let mut ctx = JobContext::new("Test", "Test job");
|
let mut ctx = JobContext::new("Test", "Test job");
|
||||||
|
|||||||
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,549 @@
|
|||||||
|
//! SQLite-dialect migrations for the libSQL/Turso backend.
|
||||||
|
//!
|
||||||
|
//! Consolidates all PostgreSQL migrations (V1-V8) into a single SQLite-compatible
|
||||||
|
//! schema. Run once on database creation; idempotent via `IF NOT EXISTS`.
|
||||||
|
|
||||||
|
/// Consolidated schema for libSQL.
|
||||||
|
///
|
||||||
|
/// Translates PostgreSQL types and features:
|
||||||
|
/// - `UUID` -> `TEXT` (store as hex string)
|
||||||
|
/// - `TIMESTAMPTZ` -> `TEXT` (ISO-8601)
|
||||||
|
/// - `JSONB` -> `TEXT` (JSON encoded)
|
||||||
|
/// - `BYTEA` -> `BLOB`
|
||||||
|
/// - `NUMERIC` -> `TEXT` (preserve precision for rust_decimal)
|
||||||
|
/// - `TEXT[]` -> `TEXT` (JSON array)
|
||||||
|
/// - `VECTOR(1536)` -> `F32_BLOB(1536)` (libsql native)
|
||||||
|
/// - `TSVECTOR` -> FTS5 virtual table
|
||||||
|
/// - `BIGSERIAL` -> `INTEGER PRIMARY KEY AUTOINCREMENT`
|
||||||
|
/// - PL/pgSQL functions -> SQLite triggers
|
||||||
|
pub const SCHEMA: &str = r#"
|
||||||
|
|
||||||
|
-- ==================== Migration tracking ====================
|
||||||
|
|
||||||
|
CREATE TABLE IF NOT EXISTS _migrations (
|
||||||
|
version INTEGER PRIMARY KEY,
|
||||||
|
name TEXT NOT NULL,
|
||||||
|
applied_at TEXT NOT NULL DEFAULT (datetime('now'))
|
||||||
|
);
|
||||||
|
|
||||||
|
-- ==================== Conversations ====================
|
||||||
|
|
||||||
|
CREATE TABLE IF NOT EXISTS conversations (
|
||||||
|
id TEXT PRIMARY KEY,
|
||||||
|
channel TEXT NOT NULL,
|
||||||
|
user_id TEXT NOT NULL,
|
||||||
|
thread_id TEXT,
|
||||||
|
started_at TEXT NOT NULL DEFAULT (datetime('now')),
|
||||||
|
last_activity TEXT NOT NULL DEFAULT (datetime('now')),
|
||||||
|
metadata TEXT NOT NULL DEFAULT '{}'
|
||||||
|
);
|
||||||
|
|
||||||
|
CREATE INDEX IF NOT EXISTS idx_conversations_channel ON conversations(channel);
|
||||||
|
CREATE INDEX IF NOT EXISTS idx_conversations_user ON conversations(user_id);
|
||||||
|
CREATE INDEX IF NOT EXISTS idx_conversations_last_activity ON conversations(last_activity);
|
||||||
|
|
||||||
|
CREATE TABLE IF NOT EXISTS conversation_messages (
|
||||||
|
id TEXT PRIMARY KEY,
|
||||||
|
conversation_id TEXT NOT NULL REFERENCES conversations(id) ON DELETE CASCADE,
|
||||||
|
role TEXT NOT NULL,
|
||||||
|
content TEXT NOT NULL,
|
||||||
|
created_at TEXT NOT NULL DEFAULT (datetime('now'))
|
||||||
|
);
|
||||||
|
|
||||||
|
CREATE INDEX IF NOT EXISTS idx_conversation_messages_conversation
|
||||||
|
ON conversation_messages(conversation_id);
|
||||||
|
|
||||||
|
-- ==================== Agent Jobs ====================
|
||||||
|
|
||||||
|
CREATE TABLE IF NOT EXISTS agent_jobs (
|
||||||
|
id TEXT PRIMARY KEY,
|
||||||
|
marketplace_job_id TEXT,
|
||||||
|
conversation_id TEXT REFERENCES conversations(id),
|
||||||
|
title TEXT NOT NULL,
|
||||||
|
description TEXT NOT NULL,
|
||||||
|
category TEXT,
|
||||||
|
status TEXT NOT NULL,
|
||||||
|
source TEXT NOT NULL,
|
||||||
|
user_id TEXT NOT NULL DEFAULT 'default',
|
||||||
|
project_dir TEXT,
|
||||||
|
job_mode TEXT NOT NULL DEFAULT 'worker',
|
||||||
|
budget_amount TEXT,
|
||||||
|
budget_token TEXT,
|
||||||
|
bid_amount TEXT,
|
||||||
|
estimated_cost TEXT,
|
||||||
|
estimated_time_secs INTEGER,
|
||||||
|
estimated_value TEXT,
|
||||||
|
actual_cost TEXT,
|
||||||
|
actual_time_secs INTEGER,
|
||||||
|
success INTEGER,
|
||||||
|
failure_reason TEXT,
|
||||||
|
stuck_since TEXT,
|
||||||
|
repair_attempts INTEGER NOT NULL DEFAULT 0,
|
||||||
|
created_at TEXT NOT NULL DEFAULT (datetime('now')),
|
||||||
|
started_at TEXT,
|
||||||
|
completed_at TEXT
|
||||||
|
);
|
||||||
|
|
||||||
|
CREATE INDEX IF NOT EXISTS idx_agent_jobs_status ON agent_jobs(status);
|
||||||
|
CREATE INDEX IF NOT EXISTS idx_agent_jobs_marketplace ON agent_jobs(marketplace_job_id);
|
||||||
|
CREATE INDEX IF NOT EXISTS idx_agent_jobs_conversation ON agent_jobs(conversation_id);
|
||||||
|
CREATE INDEX IF NOT EXISTS idx_agent_jobs_source ON agent_jobs(source);
|
||||||
|
CREATE INDEX IF NOT EXISTS idx_agent_jobs_user ON agent_jobs(user_id);
|
||||||
|
CREATE INDEX IF NOT EXISTS idx_agent_jobs_created ON agent_jobs(created_at DESC);
|
||||||
|
|
||||||
|
CREATE TABLE IF NOT EXISTS job_actions (
|
||||||
|
id TEXT PRIMARY KEY,
|
||||||
|
job_id TEXT NOT NULL REFERENCES agent_jobs(id) ON DELETE CASCADE,
|
||||||
|
sequence_num INTEGER NOT NULL,
|
||||||
|
tool_name TEXT NOT NULL,
|
||||||
|
input TEXT NOT NULL,
|
||||||
|
output_raw TEXT,
|
||||||
|
output_sanitized TEXT,
|
||||||
|
sanitization_warnings TEXT,
|
||||||
|
cost TEXT,
|
||||||
|
duration_ms INTEGER,
|
||||||
|
success INTEGER NOT NULL,
|
||||||
|
error_message TEXT,
|
||||||
|
created_at TEXT NOT NULL DEFAULT (datetime('now')),
|
||||||
|
UNIQUE(job_id, sequence_num)
|
||||||
|
);
|
||||||
|
|
||||||
|
CREATE INDEX IF NOT EXISTS idx_job_actions_job_id ON job_actions(job_id);
|
||||||
|
CREATE INDEX IF NOT EXISTS idx_job_actions_tool ON job_actions(tool_name);
|
||||||
|
|
||||||
|
-- ==================== Dynamic Tools ====================
|
||||||
|
|
||||||
|
CREATE TABLE IF NOT EXISTS dynamic_tools (
|
||||||
|
id TEXT PRIMARY KEY,
|
||||||
|
name TEXT NOT NULL UNIQUE,
|
||||||
|
description TEXT NOT NULL,
|
||||||
|
parameters_schema TEXT NOT NULL,
|
||||||
|
code TEXT NOT NULL,
|
||||||
|
sandbox_config TEXT NOT NULL,
|
||||||
|
created_by_job_id TEXT REFERENCES agent_jobs(id),
|
||||||
|
success_count INTEGER NOT NULL DEFAULT 0,
|
||||||
|
failure_count INTEGER NOT NULL DEFAULT 0,
|
||||||
|
last_error TEXT,
|
||||||
|
status TEXT NOT NULL DEFAULT 'active',
|
||||||
|
created_at TEXT NOT NULL DEFAULT (datetime('now')),
|
||||||
|
updated_at TEXT NOT NULL DEFAULT (datetime('now'))
|
||||||
|
);
|
||||||
|
|
||||||
|
CREATE INDEX IF NOT EXISTS idx_dynamic_tools_status ON dynamic_tools(status);
|
||||||
|
CREATE INDEX IF NOT EXISTS idx_dynamic_tools_name ON dynamic_tools(name);
|
||||||
|
|
||||||
|
-- ==================== LLM Calls ====================
|
||||||
|
|
||||||
|
CREATE TABLE IF NOT EXISTS llm_calls (
|
||||||
|
id TEXT PRIMARY KEY,
|
||||||
|
job_id TEXT REFERENCES agent_jobs(id) ON DELETE CASCADE,
|
||||||
|
conversation_id TEXT REFERENCES conversations(id),
|
||||||
|
provider TEXT NOT NULL,
|
||||||
|
model TEXT NOT NULL,
|
||||||
|
input_tokens INTEGER NOT NULL,
|
||||||
|
output_tokens INTEGER NOT NULL,
|
||||||
|
cost TEXT NOT NULL,
|
||||||
|
purpose TEXT,
|
||||||
|
created_at TEXT NOT NULL DEFAULT (datetime('now'))
|
||||||
|
);
|
||||||
|
|
||||||
|
CREATE INDEX IF NOT EXISTS idx_llm_calls_job ON llm_calls(job_id);
|
||||||
|
CREATE INDEX IF NOT EXISTS idx_llm_calls_conversation ON llm_calls(conversation_id);
|
||||||
|
CREATE INDEX IF NOT EXISTS idx_llm_calls_provider ON llm_calls(provider);
|
||||||
|
|
||||||
|
-- ==================== Estimation ====================
|
||||||
|
|
||||||
|
CREATE TABLE IF NOT EXISTS estimation_snapshots (
|
||||||
|
id TEXT PRIMARY KEY,
|
||||||
|
job_id TEXT NOT NULL REFERENCES agent_jobs(id) ON DELETE CASCADE,
|
||||||
|
category TEXT NOT NULL,
|
||||||
|
tool_names TEXT NOT NULL DEFAULT '[]',
|
||||||
|
estimated_cost TEXT NOT NULL,
|
||||||
|
actual_cost TEXT,
|
||||||
|
estimated_time_secs INTEGER NOT NULL,
|
||||||
|
actual_time_secs INTEGER,
|
||||||
|
estimated_value TEXT NOT NULL,
|
||||||
|
actual_value TEXT,
|
||||||
|
created_at TEXT NOT NULL DEFAULT (datetime('now'))
|
||||||
|
);
|
||||||
|
|
||||||
|
CREATE INDEX IF NOT EXISTS idx_estimation_category ON estimation_snapshots(category);
|
||||||
|
CREATE INDEX IF NOT EXISTS idx_estimation_job ON estimation_snapshots(job_id);
|
||||||
|
|
||||||
|
-- ==================== Self Repair ====================
|
||||||
|
|
||||||
|
CREATE TABLE IF NOT EXISTS repair_attempts (
|
||||||
|
id TEXT PRIMARY KEY,
|
||||||
|
target_type TEXT NOT NULL,
|
||||||
|
target_id TEXT NOT NULL,
|
||||||
|
diagnosis TEXT NOT NULL,
|
||||||
|
action_taken TEXT NOT NULL,
|
||||||
|
success INTEGER NOT NULL,
|
||||||
|
error_message TEXT,
|
||||||
|
created_at TEXT NOT NULL DEFAULT (datetime('now'))
|
||||||
|
);
|
||||||
|
|
||||||
|
CREATE INDEX IF NOT EXISTS idx_repair_attempts_target ON repair_attempts(target_type, target_id);
|
||||||
|
CREATE INDEX IF NOT EXISTS idx_repair_attempts_created ON repair_attempts(created_at);
|
||||||
|
|
||||||
|
-- ==================== Workspace: Memory Documents ====================
|
||||||
|
|
||||||
|
CREATE TABLE IF NOT EXISTS memory_documents (
|
||||||
|
id TEXT PRIMARY KEY,
|
||||||
|
user_id TEXT NOT NULL,
|
||||||
|
agent_id TEXT,
|
||||||
|
path TEXT NOT NULL,
|
||||||
|
content TEXT NOT NULL,
|
||||||
|
created_at TEXT NOT NULL DEFAULT (datetime('now')),
|
||||||
|
updated_at TEXT NOT NULL DEFAULT (datetime('now')),
|
||||||
|
metadata TEXT NOT NULL DEFAULT '{}',
|
||||||
|
UNIQUE (user_id, agent_id, path)
|
||||||
|
);
|
||||||
|
|
||||||
|
CREATE INDEX IF NOT EXISTS idx_memory_documents_user ON memory_documents(user_id);
|
||||||
|
CREATE INDEX IF NOT EXISTS idx_memory_documents_path ON memory_documents(user_id, path);
|
||||||
|
CREATE INDEX IF NOT EXISTS idx_memory_documents_updated ON memory_documents(updated_at DESC);
|
||||||
|
|
||||||
|
-- Trigger to auto-update updated_at on memory_documents
|
||||||
|
CREATE TRIGGER IF NOT EXISTS update_memory_documents_updated_at
|
||||||
|
AFTER UPDATE ON memory_documents
|
||||||
|
FOR EACH ROW
|
||||||
|
WHEN NEW.updated_at = OLD.updated_at
|
||||||
|
BEGIN
|
||||||
|
UPDATE memory_documents SET updated_at = datetime('now') WHERE id = NEW.id;
|
||||||
|
END;
|
||||||
|
|
||||||
|
-- ==================== Workspace: Memory Chunks ====================
|
||||||
|
|
||||||
|
CREATE TABLE IF NOT EXISTS memory_chunks (
|
||||||
|
_rowid INTEGER PRIMARY KEY AUTOINCREMENT,
|
||||||
|
id TEXT NOT NULL UNIQUE,
|
||||||
|
document_id TEXT NOT NULL REFERENCES memory_documents(id) ON DELETE CASCADE,
|
||||||
|
chunk_index INTEGER NOT NULL,
|
||||||
|
content TEXT NOT NULL,
|
||||||
|
embedding F32_BLOB(1536),
|
||||||
|
created_at TEXT NOT NULL DEFAULT (datetime('now')),
|
||||||
|
UNIQUE (document_id, chunk_index)
|
||||||
|
);
|
||||||
|
|
||||||
|
CREATE INDEX IF NOT EXISTS idx_memory_chunks_document ON memory_chunks(document_id);
|
||||||
|
|
||||||
|
-- Vector index for semantic search (libSQL native)
|
||||||
|
CREATE INDEX IF NOT EXISTS idx_memory_chunks_embedding
|
||||||
|
ON memory_chunks (libsql_vector_idx(embedding));
|
||||||
|
|
||||||
|
-- FTS5 virtual table for full-text search
|
||||||
|
CREATE VIRTUAL TABLE IF NOT EXISTS memory_chunks_fts USING fts5(
|
||||||
|
content,
|
||||||
|
content='memory_chunks',
|
||||||
|
content_rowid='_rowid'
|
||||||
|
);
|
||||||
|
|
||||||
|
-- Triggers to keep FTS5 in sync with memory_chunks
|
||||||
|
CREATE TRIGGER IF NOT EXISTS memory_chunks_fts_insert AFTER INSERT ON memory_chunks BEGIN
|
||||||
|
INSERT INTO memory_chunks_fts(rowid, content) VALUES (new._rowid, new.content);
|
||||||
|
END;
|
||||||
|
|
||||||
|
CREATE TRIGGER IF NOT EXISTS memory_chunks_fts_delete AFTER DELETE ON memory_chunks BEGIN
|
||||||
|
INSERT INTO memory_chunks_fts(memory_chunks_fts, rowid, content)
|
||||||
|
VALUES ('delete', old._rowid, old.content);
|
||||||
|
END;
|
||||||
|
|
||||||
|
CREATE TRIGGER IF NOT EXISTS memory_chunks_fts_update AFTER UPDATE ON memory_chunks BEGIN
|
||||||
|
INSERT INTO memory_chunks_fts(memory_chunks_fts, rowid, content)
|
||||||
|
VALUES ('delete', old._rowid, old.content);
|
||||||
|
INSERT INTO memory_chunks_fts(rowid, content) VALUES (new._rowid, new.content);
|
||||||
|
END;
|
||||||
|
|
||||||
|
-- ==================== Workspace: Heartbeat State ====================
|
||||||
|
|
||||||
|
CREATE TABLE IF NOT EXISTS heartbeat_state (
|
||||||
|
id TEXT PRIMARY KEY,
|
||||||
|
user_id TEXT NOT NULL,
|
||||||
|
agent_id TEXT,
|
||||||
|
last_run TEXT,
|
||||||
|
next_run TEXT,
|
||||||
|
interval_seconds INTEGER NOT NULL DEFAULT 1800,
|
||||||
|
enabled INTEGER NOT NULL DEFAULT 1,
|
||||||
|
consecutive_failures INTEGER NOT NULL DEFAULT 0,
|
||||||
|
last_checks TEXT NOT NULL DEFAULT '{}',
|
||||||
|
UNIQUE (user_id, agent_id)
|
||||||
|
);
|
||||||
|
|
||||||
|
CREATE INDEX IF NOT EXISTS idx_heartbeat_user ON heartbeat_state(user_id);
|
||||||
|
|
||||||
|
-- ==================== Secrets ====================
|
||||||
|
|
||||||
|
CREATE TABLE IF NOT EXISTS secrets (
|
||||||
|
id TEXT PRIMARY KEY,
|
||||||
|
user_id TEXT NOT NULL,
|
||||||
|
name TEXT NOT NULL,
|
||||||
|
encrypted_value BLOB NOT NULL,
|
||||||
|
key_salt BLOB NOT NULL,
|
||||||
|
provider TEXT,
|
||||||
|
expires_at TEXT,
|
||||||
|
last_used_at TEXT,
|
||||||
|
usage_count INTEGER NOT NULL DEFAULT 0,
|
||||||
|
created_at TEXT NOT NULL DEFAULT (datetime('now')),
|
||||||
|
updated_at TEXT NOT NULL DEFAULT (datetime('now')),
|
||||||
|
UNIQUE (user_id, name)
|
||||||
|
);
|
||||||
|
|
||||||
|
CREATE INDEX IF NOT EXISTS idx_secrets_user ON secrets(user_id);
|
||||||
|
|
||||||
|
-- ==================== WASM Tools ====================
|
||||||
|
|
||||||
|
CREATE TABLE IF NOT EXISTS wasm_tools (
|
||||||
|
id TEXT PRIMARY KEY,
|
||||||
|
user_id TEXT NOT NULL,
|
||||||
|
name TEXT NOT NULL,
|
||||||
|
version TEXT NOT NULL DEFAULT '1.0.0',
|
||||||
|
description TEXT NOT NULL,
|
||||||
|
wasm_binary BLOB NOT NULL,
|
||||||
|
binary_hash BLOB NOT NULL,
|
||||||
|
parameters_schema TEXT NOT NULL,
|
||||||
|
source_url TEXT,
|
||||||
|
trust_level TEXT NOT NULL DEFAULT 'user',
|
||||||
|
status TEXT NOT NULL DEFAULT 'active',
|
||||||
|
created_at TEXT NOT NULL DEFAULT (datetime('now')),
|
||||||
|
updated_at TEXT NOT NULL DEFAULT (datetime('now')),
|
||||||
|
UNIQUE (user_id, name, version)
|
||||||
|
);
|
||||||
|
|
||||||
|
CREATE INDEX IF NOT EXISTS idx_wasm_tools_user ON wasm_tools(user_id);
|
||||||
|
CREATE INDEX IF NOT EXISTS idx_wasm_tools_name ON wasm_tools(user_id, name);
|
||||||
|
CREATE INDEX IF NOT EXISTS idx_wasm_tools_status ON wasm_tools(status);
|
||||||
|
|
||||||
|
-- ==================== Tool Capabilities ====================
|
||||||
|
|
||||||
|
CREATE TABLE IF NOT EXISTS tool_capabilities (
|
||||||
|
id TEXT PRIMARY KEY,
|
||||||
|
wasm_tool_id TEXT NOT NULL REFERENCES wasm_tools(id) ON DELETE CASCADE,
|
||||||
|
http_allowlist TEXT NOT NULL DEFAULT '[]',
|
||||||
|
allowed_secrets TEXT NOT NULL DEFAULT '[]',
|
||||||
|
tool_aliases TEXT NOT NULL DEFAULT '{}',
|
||||||
|
requests_per_minute INTEGER NOT NULL DEFAULT 60,
|
||||||
|
requests_per_hour INTEGER NOT NULL DEFAULT 1000,
|
||||||
|
max_request_body_bytes INTEGER NOT NULL DEFAULT 1048576,
|
||||||
|
max_response_body_bytes INTEGER NOT NULL DEFAULT 10485760,
|
||||||
|
workspace_read_prefixes TEXT NOT NULL DEFAULT '[]',
|
||||||
|
http_timeout_secs INTEGER NOT NULL DEFAULT 30,
|
||||||
|
created_at TEXT NOT NULL DEFAULT (datetime('now')),
|
||||||
|
updated_at TEXT NOT NULL DEFAULT (datetime('now')),
|
||||||
|
UNIQUE (wasm_tool_id)
|
||||||
|
);
|
||||||
|
|
||||||
|
-- ==================== Leak Detection Patterns ====================
|
||||||
|
|
||||||
|
CREATE TABLE IF NOT EXISTS leak_detection_patterns (
|
||||||
|
id TEXT PRIMARY KEY,
|
||||||
|
name TEXT NOT NULL UNIQUE,
|
||||||
|
pattern TEXT NOT NULL,
|
||||||
|
severity TEXT NOT NULL DEFAULT 'high',
|
||||||
|
action TEXT NOT NULL DEFAULT 'block',
|
||||||
|
enabled INTEGER NOT NULL DEFAULT 1,
|
||||||
|
created_at TEXT NOT NULL DEFAULT (datetime('now'))
|
||||||
|
);
|
||||||
|
|
||||||
|
-- ==================== Rate Limit State ====================
|
||||||
|
|
||||||
|
CREATE TABLE IF NOT EXISTS tool_rate_limit_state (
|
||||||
|
id TEXT PRIMARY KEY,
|
||||||
|
wasm_tool_id TEXT NOT NULL REFERENCES wasm_tools(id) ON DELETE CASCADE,
|
||||||
|
user_id TEXT NOT NULL,
|
||||||
|
minute_window_start TEXT NOT NULL DEFAULT (datetime('now')),
|
||||||
|
minute_count INTEGER NOT NULL DEFAULT 0,
|
||||||
|
hour_window_start TEXT NOT NULL DEFAULT (datetime('now')),
|
||||||
|
hour_count INTEGER NOT NULL DEFAULT 0,
|
||||||
|
UNIQUE (wasm_tool_id, user_id)
|
||||||
|
);
|
||||||
|
|
||||||
|
-- ==================== Secret Usage Audit Log ====================
|
||||||
|
|
||||||
|
CREATE TABLE IF NOT EXISTS secret_usage_log (
|
||||||
|
id TEXT PRIMARY KEY,
|
||||||
|
secret_id TEXT NOT NULL REFERENCES secrets(id) ON DELETE CASCADE,
|
||||||
|
wasm_tool_id TEXT REFERENCES wasm_tools(id) ON DELETE SET NULL,
|
||||||
|
user_id TEXT NOT NULL,
|
||||||
|
target_host TEXT NOT NULL,
|
||||||
|
target_path TEXT,
|
||||||
|
success INTEGER NOT NULL,
|
||||||
|
error_message TEXT,
|
||||||
|
created_at TEXT NOT NULL DEFAULT (datetime('now'))
|
||||||
|
);
|
||||||
|
|
||||||
|
CREATE INDEX IF NOT EXISTS idx_secret_usage_user ON secret_usage_log(user_id);
|
||||||
|
|
||||||
|
-- ==================== Leak Detection Events ====================
|
||||||
|
|
||||||
|
CREATE TABLE IF NOT EXISTS leak_detection_events (
|
||||||
|
id TEXT PRIMARY KEY,
|
||||||
|
pattern_id TEXT REFERENCES leak_detection_patterns(id) ON DELETE SET NULL,
|
||||||
|
wasm_tool_id TEXT REFERENCES wasm_tools(id) ON DELETE SET NULL,
|
||||||
|
user_id TEXT NOT NULL,
|
||||||
|
source TEXT NOT NULL,
|
||||||
|
action_taken TEXT NOT NULL,
|
||||||
|
context_preview TEXT,
|
||||||
|
created_at TEXT NOT NULL DEFAULT (datetime('now'))
|
||||||
|
);
|
||||||
|
|
||||||
|
-- ==================== Tool Failures ====================
|
||||||
|
|
||||||
|
CREATE TABLE IF NOT EXISTS tool_failures (
|
||||||
|
id TEXT PRIMARY KEY,
|
||||||
|
tool_name TEXT NOT NULL UNIQUE,
|
||||||
|
error_message TEXT,
|
||||||
|
error_count INTEGER DEFAULT 1,
|
||||||
|
first_failure TEXT DEFAULT (datetime('now')),
|
||||||
|
last_failure TEXT DEFAULT (datetime('now')),
|
||||||
|
last_build_result TEXT,
|
||||||
|
repaired_at TEXT,
|
||||||
|
repair_attempts INTEGER DEFAULT 0
|
||||||
|
);
|
||||||
|
|
||||||
|
CREATE INDEX IF NOT EXISTS idx_tool_failures_name ON tool_failures(tool_name);
|
||||||
|
|
||||||
|
-- ==================== Job Events ====================
|
||||||
|
|
||||||
|
CREATE TABLE IF NOT EXISTS job_events (
|
||||||
|
id INTEGER PRIMARY KEY AUTOINCREMENT,
|
||||||
|
job_id TEXT NOT NULL REFERENCES agent_jobs(id),
|
||||||
|
event_type TEXT NOT NULL,
|
||||||
|
data TEXT NOT NULL,
|
||||||
|
created_at TEXT NOT NULL DEFAULT (datetime('now'))
|
||||||
|
);
|
||||||
|
|
||||||
|
CREATE INDEX IF NOT EXISTS idx_job_events_job ON job_events(job_id, id);
|
||||||
|
|
||||||
|
-- ==================== Routines ====================
|
||||||
|
|
||||||
|
CREATE TABLE IF NOT EXISTS routines (
|
||||||
|
id TEXT PRIMARY KEY,
|
||||||
|
name TEXT NOT NULL,
|
||||||
|
description TEXT NOT NULL DEFAULT '',
|
||||||
|
user_id TEXT NOT NULL,
|
||||||
|
enabled INTEGER NOT NULL DEFAULT 1,
|
||||||
|
trigger_type TEXT NOT NULL,
|
||||||
|
trigger_config TEXT NOT NULL,
|
||||||
|
action_type TEXT NOT NULL,
|
||||||
|
action_config TEXT NOT NULL,
|
||||||
|
cooldown_secs INTEGER NOT NULL DEFAULT 300,
|
||||||
|
max_concurrent INTEGER NOT NULL DEFAULT 1,
|
||||||
|
dedup_window_secs INTEGER,
|
||||||
|
notify_channel TEXT,
|
||||||
|
notify_user TEXT NOT NULL DEFAULT 'default',
|
||||||
|
notify_on_success INTEGER NOT NULL DEFAULT 0,
|
||||||
|
notify_on_failure INTEGER NOT NULL DEFAULT 1,
|
||||||
|
notify_on_attention INTEGER NOT NULL DEFAULT 1,
|
||||||
|
state TEXT NOT NULL DEFAULT '{}',
|
||||||
|
last_run_at TEXT,
|
||||||
|
next_fire_at TEXT,
|
||||||
|
run_count INTEGER NOT NULL DEFAULT 0,
|
||||||
|
consecutive_failures INTEGER NOT NULL DEFAULT 0,
|
||||||
|
created_at TEXT NOT NULL DEFAULT (datetime('now')),
|
||||||
|
updated_at TEXT NOT NULL DEFAULT (datetime('now')),
|
||||||
|
UNIQUE (user_id, name)
|
||||||
|
);
|
||||||
|
|
||||||
|
CREATE INDEX IF NOT EXISTS idx_routines_user ON routines(user_id);
|
||||||
|
|
||||||
|
-- ==================== Routine Runs ====================
|
||||||
|
|
||||||
|
CREATE TABLE IF NOT EXISTS routine_runs (
|
||||||
|
id TEXT PRIMARY KEY,
|
||||||
|
routine_id TEXT NOT NULL REFERENCES routines(id) ON DELETE CASCADE,
|
||||||
|
trigger_type TEXT NOT NULL,
|
||||||
|
trigger_detail TEXT,
|
||||||
|
started_at TEXT NOT NULL DEFAULT (datetime('now')),
|
||||||
|
completed_at TEXT,
|
||||||
|
status TEXT NOT NULL DEFAULT 'running',
|
||||||
|
result_summary TEXT,
|
||||||
|
tokens_used INTEGER,
|
||||||
|
job_id TEXT REFERENCES agent_jobs(id),
|
||||||
|
created_at TEXT NOT NULL DEFAULT (datetime('now'))
|
||||||
|
);
|
||||||
|
|
||||||
|
CREATE INDEX IF NOT EXISTS idx_routine_runs_routine ON routine_runs(routine_id);
|
||||||
|
|
||||||
|
-- ==================== Settings ====================
|
||||||
|
|
||||||
|
CREATE TABLE IF NOT EXISTS settings (
|
||||||
|
user_id TEXT NOT NULL,
|
||||||
|
key TEXT NOT NULL,
|
||||||
|
value TEXT NOT NULL,
|
||||||
|
updated_at TEXT NOT NULL DEFAULT (datetime('now')),
|
||||||
|
PRIMARY KEY (user_id, key)
|
||||||
|
);
|
||||||
|
|
||||||
|
CREATE INDEX IF NOT EXISTS idx_settings_user ON settings(user_id);
|
||||||
|
|
||||||
|
-- ==================== Missing indexes (parity with PostgreSQL) ====================
|
||||||
|
|
||||||
|
-- agent_jobs
|
||||||
|
CREATE INDEX IF NOT EXISTS idx_agent_jobs_stuck ON agent_jobs(stuck_since);
|
||||||
|
|
||||||
|
-- secrets
|
||||||
|
CREATE INDEX IF NOT EXISTS idx_secrets_provider ON secrets(provider);
|
||||||
|
CREATE INDEX IF NOT EXISTS idx_secrets_expires ON secrets(expires_at);
|
||||||
|
|
||||||
|
-- wasm_tools
|
||||||
|
CREATE INDEX IF NOT EXISTS idx_wasm_tools_trust ON wasm_tools(trust_level);
|
||||||
|
|
||||||
|
-- tool_capabilities
|
||||||
|
CREATE INDEX IF NOT EXISTS idx_tool_capabilities_tool ON tool_capabilities(wasm_tool_id);
|
||||||
|
|
||||||
|
-- leak_detection_patterns
|
||||||
|
CREATE INDEX IF NOT EXISTS idx_leak_patterns_enabled ON leak_detection_patterns(enabled);
|
||||||
|
|
||||||
|
-- tool_rate_limit_state
|
||||||
|
CREATE INDEX IF NOT EXISTS idx_rate_limit_tool ON tool_rate_limit_state(wasm_tool_id);
|
||||||
|
|
||||||
|
-- secret_usage_log
|
||||||
|
CREATE INDEX IF NOT EXISTS idx_secret_usage_secret ON secret_usage_log(secret_id);
|
||||||
|
CREATE INDEX IF NOT EXISTS idx_secret_usage_tool ON secret_usage_log(wasm_tool_id);
|
||||||
|
CREATE INDEX IF NOT EXISTS idx_secret_usage_created ON secret_usage_log(created_at DESC);
|
||||||
|
|
||||||
|
-- leak_detection_events
|
||||||
|
CREATE INDEX IF NOT EXISTS idx_leak_events_pattern ON leak_detection_events(pattern_id);
|
||||||
|
CREATE INDEX IF NOT EXISTS idx_leak_events_tool ON leak_detection_events(wasm_tool_id);
|
||||||
|
CREATE INDEX IF NOT EXISTS idx_leak_events_user ON leak_detection_events(user_id);
|
||||||
|
CREATE INDEX IF NOT EXISTS idx_leak_events_created ON leak_detection_events(created_at DESC);
|
||||||
|
|
||||||
|
-- tool_failures
|
||||||
|
CREATE INDEX IF NOT EXISTS idx_tool_failures_count ON tool_failures(error_count DESC);
|
||||||
|
CREATE INDEX IF NOT EXISTS idx_tool_failures_unrepaired ON tool_failures(tool_name);
|
||||||
|
|
||||||
|
-- routines
|
||||||
|
CREATE INDEX IF NOT EXISTS idx_routines_next_fire ON routines(next_fire_at);
|
||||||
|
CREATE INDEX IF NOT EXISTS idx_routines_event_triggers ON routines(user_id);
|
||||||
|
|
||||||
|
-- routine_runs
|
||||||
|
CREATE INDEX IF NOT EXISTS idx_routine_runs_status ON routine_runs(status);
|
||||||
|
|
||||||
|
-- heartbeat_state
|
||||||
|
CREATE INDEX IF NOT EXISTS idx_heartbeat_next_run ON heartbeat_state(next_run);
|
||||||
|
|
||||||
|
-- ==================== Seed data ====================
|
||||||
|
|
||||||
|
-- Pre-populate leak detection patterns (matches PostgreSQL V2 migration).
|
||||||
|
INSERT OR IGNORE INTO leak_detection_patterns (id, name, pattern, severity, action, enabled, created_at) VALUES
|
||||||
|
('550e8400-e29b-41d4-a716-446655440001', 'openai_api_key', 'sk-(?:proj-)?[a-zA-Z0-9]{20,}(?:T3BlbkFJ[a-zA-Z0-9_-]*)?', 'critical', 'block', 1, datetime('now')),
|
||||||
|
('550e8400-e29b-41d4-a716-446655440002', 'anthropic_api_key', 'sk-ant-api[a-zA-Z0-9_-]{90,}', 'critical', 'block', 1, datetime('now')),
|
||||||
|
('550e8400-e29b-41d4-a716-446655440003', 'aws_access_key', 'AKIA[0-9A-Z]{16}', 'critical', 'block', 1, datetime('now')),
|
||||||
|
('550e8400-e29b-41d4-a716-446655440004', 'aws_secret_key', '(?<![A-Za-z0-9/+=])[A-Za-z0-9/+=]{40}(?![A-Za-z0-9/+=])', 'high', 'block', 1, datetime('now')),
|
||||||
|
('550e8400-e29b-41d4-a716-446655440005', 'github_token', 'gh[pousr]_[A-Za-z0-9_]{36,}', 'critical', 'block', 1, datetime('now')),
|
||||||
|
('550e8400-e29b-41d4-a716-446655440006', 'github_fine_grained_pat', 'github_pat_[a-zA-Z0-9]{22}_[a-zA-Z0-9]{59}', 'critical', 'block', 1, datetime('now')),
|
||||||
|
('550e8400-e29b-41d4-a716-446655440007', 'stripe_api_key', 'sk_(?:live|test)_[a-zA-Z0-9]{24,}', 'critical', 'block', 1, datetime('now')),
|
||||||
|
('550e8400-e29b-41d4-a716-446655440008', 'nearai_session', 'sess_[a-zA-Z0-9]{32,}', 'critical', 'block', 1, datetime('now')),
|
||||||
|
('550e8400-e29b-41d4-a716-446655440009', 'bearer_token', 'Bearer\s+[a-zA-Z0-9_-]{20,}', 'high', 'redact', 1, datetime('now')),
|
||||||
|
('550e8400-e29b-41d4-a716-44665544000a', 'pem_private_key', '-----BEGIN\s+(?:RSA\s+)?PRIVATE\s+KEY-----', 'critical', 'block', 1, datetime('now')),
|
||||||
|
('550e8400-e29b-41d4-a716-44665544000b', 'ssh_private_key', '-----BEGIN\s+(?:OPENSSH|EC|DSA)\s+PRIVATE\s+KEY-----', 'critical', 'block', 1, datetime('now')),
|
||||||
|
('550e8400-e29b-41d4-a716-44665544000c', 'google_api_key', 'AIza[0-9A-Za-z_-]{35}', 'high', 'block', 1, datetime('now')),
|
||||||
|
('550e8400-e29b-41d4-a716-44665544000d', 'slack_token', 'xox[baprs]-[0-9a-zA-Z-]{10,}', 'high', 'block', 1, datetime('now')),
|
||||||
|
('550e8400-e29b-41d4-a716-44665544000e', 'discord_token', '[MN][A-Za-z\d]{23,}\.[\w-]{6}\.[\w-]{27}', 'high', 'block', 1, datetime('now')),
|
||||||
|
('550e8400-e29b-41d4-a716-44665544000f', 'twilio_api_key', 'SK[a-fA-F0-9]{32}', 'high', 'block', 1, datetime('now')),
|
||||||
|
('550e8400-e29b-41d4-a716-446655440010', 'sendgrid_api_key', 'SG\.[a-zA-Z0-9_-]{22}\.[a-zA-Z0-9_-]{43}', 'high', 'block', 1, datetime('now')),
|
||||||
|
('550e8400-e29b-41d4-a716-446655440011', 'mailchimp_api_key', '[a-f0-9]{32}-us[0-9]{1,2}', 'medium', 'block', 1, datetime('now')),
|
||||||
|
('550e8400-e29b-41d4-a716-446655440012', 'high_entropy_hex', '(?<![a-fA-F0-9])[a-fA-F0-9]{64}(?![a-fA-F0-9])', 'medium', 'warn', 1, datetime('now'));
|
||||||
|
|
||||||
|
"#;
|
||||||
+538
@@ -0,0 +1,538 @@
|
|||||||
|
//! Database abstraction layer.
|
||||||
|
//!
|
||||||
|
//! Provides a backend-agnostic `Database` trait that unifies all persistence
|
||||||
|
//! operations. Two implementations exist behind feature flags:
|
||||||
|
//!
|
||||||
|
//! - `postgres` (default): Uses `deadpool-postgres` + `tokio-postgres`
|
||||||
|
//! - `libsql`: Uses libSQL (Turso's SQLite fork) for embedded/edge deployment
|
||||||
|
//!
|
||||||
|
//! The existing `Store`, `Repository`, `SecretsStore`, and `WasmToolStore`
|
||||||
|
//! types become thin wrappers that delegate to `Arc<dyn Database>`.
|
||||||
|
|
||||||
|
#[cfg(feature = "postgres")]
|
||||||
|
pub mod postgres;
|
||||||
|
|
||||||
|
#[cfg(feature = "libsql")]
|
||||||
|
pub mod libsql_backend;
|
||||||
|
|
||||||
|
#[cfg(feature = "libsql")]
|
||||||
|
pub mod libsql_migrations;
|
||||||
|
|
||||||
|
use std::collections::HashMap;
|
||||||
|
use std::sync::Arc;
|
||||||
|
|
||||||
|
use async_trait::async_trait;
|
||||||
|
use chrono::{DateTime, Utc};
|
||||||
|
use rust_decimal::Decimal;
|
||||||
|
use uuid::Uuid;
|
||||||
|
|
||||||
|
use crate::agent::BrokenTool;
|
||||||
|
use crate::agent::routine::{Routine, RoutineRun, RunStatus};
|
||||||
|
use crate::context::{ActionRecord, JobContext, JobState};
|
||||||
|
use crate::error::DatabaseError;
|
||||||
|
use crate::error::WorkspaceError;
|
||||||
|
use crate::history::{
|
||||||
|
ConversationMessage, ConversationSummary, JobEventRecord, LlmCallRecord, SandboxJobRecord,
|
||||||
|
SandboxJobSummary, SettingRow,
|
||||||
|
};
|
||||||
|
use crate::workspace::{MemoryChunk, MemoryDocument, WorkspaceEntry};
|
||||||
|
use crate::workspace::{SearchConfig, SearchResult};
|
||||||
|
|
||||||
|
/// Create a database backend from configuration, run migrations, and return it.
|
||||||
|
///
|
||||||
|
/// This is the shared helper for CLI commands and other call sites that need
|
||||||
|
/// a simple `Arc<dyn Database>` without retaining backend-specific handles
|
||||||
|
/// (e.g., `pg_pool` or `libsql_conn` for the secrets store). The main agent
|
||||||
|
/// startup in `main.rs` uses its own initialization block because it also
|
||||||
|
/// captures those backend-specific handles.
|
||||||
|
pub async fn connect_from_config(
|
||||||
|
config: &crate::config::DatabaseConfig,
|
||||||
|
) -> Result<Arc<dyn Database>, DatabaseError> {
|
||||||
|
match config.backend {
|
||||||
|
#[cfg(feature = "libsql")]
|
||||||
|
crate::config::DatabaseBackend::LibSql => {
|
||||||
|
use secrecy::ExposeSecret as _;
|
||||||
|
|
||||||
|
let default_path = crate::config::default_libsql_path();
|
||||||
|
let db_path = config.libsql_path.as_deref().unwrap_or(&default_path);
|
||||||
|
|
||||||
|
let backend = if let Some(ref url) = config.libsql_url {
|
||||||
|
let token = config.libsql_auth_token.as_ref().ok_or_else(|| {
|
||||||
|
DatabaseError::Pool(
|
||||||
|
"LIBSQL_AUTH_TOKEN required when LIBSQL_URL is set".to_string(),
|
||||||
|
)
|
||||||
|
})?;
|
||||||
|
libsql_backend::LibSqlBackend::new_remote_replica(
|
||||||
|
db_path,
|
||||||
|
url,
|
||||||
|
token.expose_secret(),
|
||||||
|
)
|
||||||
|
.await
|
||||||
|
.map_err(|e| DatabaseError::Pool(e.to_string()))?
|
||||||
|
} else {
|
||||||
|
libsql_backend::LibSqlBackend::new_local(db_path)
|
||||||
|
.await
|
||||||
|
.map_err(|e| DatabaseError::Pool(e.to_string()))?
|
||||||
|
};
|
||||||
|
backend.run_migrations().await?;
|
||||||
|
Ok(Arc::new(backend))
|
||||||
|
}
|
||||||
|
#[cfg(feature = "postgres")]
|
||||||
|
_ => {
|
||||||
|
let pg = postgres::PgBackend::new(config)
|
||||||
|
.await
|
||||||
|
.map_err(|e| DatabaseError::Pool(e.to_string()))?;
|
||||||
|
pg.run_migrations().await?;
|
||||||
|
Ok(Arc::new(pg))
|
||||||
|
}
|
||||||
|
#[cfg(not(feature = "postgres"))]
|
||||||
|
_ => Err(DatabaseError::Pool(
|
||||||
|
"No database backend available. Enable 'postgres' or 'libsql' feature.".to_string(),
|
||||||
|
)),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Backend-agnostic database trait.
|
||||||
|
///
|
||||||
|
/// Combines all persistence operations from Store, Repository, and related
|
||||||
|
/// stores into a single trait that can be implemented for different backends.
|
||||||
|
#[async_trait]
|
||||||
|
pub trait Database: Send + Sync {
|
||||||
|
/// Run schema migrations for this backend.
|
||||||
|
async fn run_migrations(&self) -> Result<(), DatabaseError>;
|
||||||
|
|
||||||
|
// ==================== Conversations ====================
|
||||||
|
|
||||||
|
/// Create a new conversation.
|
||||||
|
async fn create_conversation(
|
||||||
|
&self,
|
||||||
|
channel: &str,
|
||||||
|
user_id: &str,
|
||||||
|
thread_id: Option<&str>,
|
||||||
|
) -> Result<Uuid, DatabaseError>;
|
||||||
|
|
||||||
|
/// Update conversation last activity.
|
||||||
|
async fn touch_conversation(&self, id: Uuid) -> Result<(), DatabaseError>;
|
||||||
|
|
||||||
|
/// Add a message to a conversation.
|
||||||
|
async fn add_conversation_message(
|
||||||
|
&self,
|
||||||
|
conversation_id: Uuid,
|
||||||
|
role: &str,
|
||||||
|
content: &str,
|
||||||
|
) -> Result<Uuid, DatabaseError>;
|
||||||
|
|
||||||
|
/// Ensure a conversation row exists (upsert).
|
||||||
|
async fn ensure_conversation(
|
||||||
|
&self,
|
||||||
|
id: Uuid,
|
||||||
|
channel: &str,
|
||||||
|
user_id: &str,
|
||||||
|
thread_id: Option<&str>,
|
||||||
|
) -> Result<(), DatabaseError>;
|
||||||
|
|
||||||
|
/// List conversations with a title preview.
|
||||||
|
async fn list_conversations_with_preview(
|
||||||
|
&self,
|
||||||
|
user_id: &str,
|
||||||
|
channel: &str,
|
||||||
|
limit: i64,
|
||||||
|
) -> Result<Vec<ConversationSummary>, DatabaseError>;
|
||||||
|
|
||||||
|
/// Get or create the singleton assistant conversation.
|
||||||
|
async fn get_or_create_assistant_conversation(
|
||||||
|
&self,
|
||||||
|
user_id: &str,
|
||||||
|
channel: &str,
|
||||||
|
) -> Result<Uuid, DatabaseError>;
|
||||||
|
|
||||||
|
/// Create a conversation with specific metadata.
|
||||||
|
async fn create_conversation_with_metadata(
|
||||||
|
&self,
|
||||||
|
channel: &str,
|
||||||
|
user_id: &str,
|
||||||
|
metadata: &serde_json::Value,
|
||||||
|
) -> Result<Uuid, DatabaseError>;
|
||||||
|
|
||||||
|
/// Load messages with cursor-based pagination.
|
||||||
|
async fn list_conversation_messages_paginated(
|
||||||
|
&self,
|
||||||
|
conversation_id: Uuid,
|
||||||
|
before: Option<DateTime<Utc>>,
|
||||||
|
limit: i64,
|
||||||
|
) -> Result<(Vec<ConversationMessage>, bool), DatabaseError>;
|
||||||
|
|
||||||
|
/// Merge a single key into conversation metadata.
|
||||||
|
async fn update_conversation_metadata_field(
|
||||||
|
&self,
|
||||||
|
id: Uuid,
|
||||||
|
key: &str,
|
||||||
|
value: &serde_json::Value,
|
||||||
|
) -> Result<(), DatabaseError>;
|
||||||
|
|
||||||
|
/// Read conversation metadata.
|
||||||
|
async fn get_conversation_metadata(
|
||||||
|
&self,
|
||||||
|
id: Uuid,
|
||||||
|
) -> Result<Option<serde_json::Value>, DatabaseError>;
|
||||||
|
|
||||||
|
/// Load all messages for a conversation.
|
||||||
|
async fn list_conversation_messages(
|
||||||
|
&self,
|
||||||
|
conversation_id: Uuid,
|
||||||
|
) -> Result<Vec<ConversationMessage>, DatabaseError>;
|
||||||
|
|
||||||
|
/// Check if a conversation belongs to a specific user.
|
||||||
|
async fn conversation_belongs_to_user(
|
||||||
|
&self,
|
||||||
|
conversation_id: Uuid,
|
||||||
|
user_id: &str,
|
||||||
|
) -> Result<bool, DatabaseError>;
|
||||||
|
|
||||||
|
// ==================== Jobs ====================
|
||||||
|
|
||||||
|
/// Save a job context.
|
||||||
|
async fn save_job(&self, ctx: &JobContext) -> Result<(), DatabaseError>;
|
||||||
|
|
||||||
|
/// Get a job by ID.
|
||||||
|
async fn get_job(&self, id: Uuid) -> Result<Option<JobContext>, DatabaseError>;
|
||||||
|
|
||||||
|
/// Update job status.
|
||||||
|
async fn update_job_status(
|
||||||
|
&self,
|
||||||
|
id: Uuid,
|
||||||
|
status: JobState,
|
||||||
|
failure_reason: Option<&str>,
|
||||||
|
) -> Result<(), DatabaseError>;
|
||||||
|
|
||||||
|
/// Mark job as stuck.
|
||||||
|
async fn mark_job_stuck(&self, id: Uuid) -> Result<(), DatabaseError>;
|
||||||
|
|
||||||
|
/// Get stuck jobs.
|
||||||
|
async fn get_stuck_jobs(&self) -> Result<Vec<Uuid>, DatabaseError>;
|
||||||
|
|
||||||
|
// ==================== Actions ====================
|
||||||
|
|
||||||
|
/// Save a job action.
|
||||||
|
async fn save_action(&self, job_id: Uuid, action: &ActionRecord) -> Result<(), DatabaseError>;
|
||||||
|
|
||||||
|
/// Get actions for a job.
|
||||||
|
async fn get_job_actions(&self, job_id: Uuid) -> Result<Vec<ActionRecord>, DatabaseError>;
|
||||||
|
|
||||||
|
// ==================== LLM Calls ====================
|
||||||
|
|
||||||
|
/// Record an LLM call.
|
||||||
|
async fn record_llm_call(&self, record: &LlmCallRecord<'_>) -> Result<Uuid, DatabaseError>;
|
||||||
|
|
||||||
|
// ==================== Estimation Snapshots ====================
|
||||||
|
|
||||||
|
/// Save an estimation snapshot.
|
||||||
|
async fn save_estimation_snapshot(
|
||||||
|
&self,
|
||||||
|
job_id: Uuid,
|
||||||
|
category: &str,
|
||||||
|
tool_names: &[String],
|
||||||
|
estimated_cost: Decimal,
|
||||||
|
estimated_time_secs: i32,
|
||||||
|
estimated_value: Decimal,
|
||||||
|
) -> Result<Uuid, DatabaseError>;
|
||||||
|
|
||||||
|
/// Update estimation snapshot with actual values.
|
||||||
|
async fn update_estimation_actuals(
|
||||||
|
&self,
|
||||||
|
id: Uuid,
|
||||||
|
actual_cost: Decimal,
|
||||||
|
actual_time_secs: i32,
|
||||||
|
actual_value: Option<Decimal>,
|
||||||
|
) -> Result<(), DatabaseError>;
|
||||||
|
|
||||||
|
// ==================== Sandbox Jobs ====================
|
||||||
|
|
||||||
|
/// Insert a new sandbox job.
|
||||||
|
async fn save_sandbox_job(&self, job: &SandboxJobRecord) -> Result<(), DatabaseError>;
|
||||||
|
|
||||||
|
/// Get a sandbox job by ID.
|
||||||
|
async fn get_sandbox_job(&self, id: Uuid) -> Result<Option<SandboxJobRecord>, DatabaseError>;
|
||||||
|
|
||||||
|
/// List all sandbox jobs, most recent first.
|
||||||
|
async fn list_sandbox_jobs(&self) -> Result<Vec<SandboxJobRecord>, DatabaseError>;
|
||||||
|
|
||||||
|
/// Update sandbox job status.
|
||||||
|
async fn update_sandbox_job_status(
|
||||||
|
&self,
|
||||||
|
id: Uuid,
|
||||||
|
status: &str,
|
||||||
|
success: Option<bool>,
|
||||||
|
message: Option<&str>,
|
||||||
|
started_at: Option<DateTime<Utc>>,
|
||||||
|
completed_at: Option<DateTime<Utc>>,
|
||||||
|
) -> Result<(), DatabaseError>;
|
||||||
|
|
||||||
|
/// Mark stale sandbox jobs as interrupted.
|
||||||
|
async fn cleanup_stale_sandbox_jobs(&self) -> Result<u64, DatabaseError>;
|
||||||
|
|
||||||
|
/// Get sandbox job summary.
|
||||||
|
async fn sandbox_job_summary(&self) -> Result<SandboxJobSummary, DatabaseError>;
|
||||||
|
|
||||||
|
/// List sandbox jobs for a specific user, most recent first.
|
||||||
|
async fn list_sandbox_jobs_for_user(
|
||||||
|
&self,
|
||||||
|
user_id: &str,
|
||||||
|
) -> Result<Vec<SandboxJobRecord>, DatabaseError>;
|
||||||
|
|
||||||
|
/// Get sandbox job summary for a specific user.
|
||||||
|
async fn sandbox_job_summary_for_user(
|
||||||
|
&self,
|
||||||
|
user_id: &str,
|
||||||
|
) -> Result<SandboxJobSummary, DatabaseError>;
|
||||||
|
|
||||||
|
/// Check if a sandbox job belongs to a specific user.
|
||||||
|
async fn sandbox_job_belongs_to_user(
|
||||||
|
&self,
|
||||||
|
job_id: Uuid,
|
||||||
|
user_id: &str,
|
||||||
|
) -> Result<bool, DatabaseError>;
|
||||||
|
|
||||||
|
/// Update sandbox job mode.
|
||||||
|
async fn update_sandbox_job_mode(&self, id: Uuid, mode: &str) -> Result<(), DatabaseError>;
|
||||||
|
|
||||||
|
/// Get sandbox job mode.
|
||||||
|
async fn get_sandbox_job_mode(&self, id: Uuid) -> Result<Option<String>, DatabaseError>;
|
||||||
|
|
||||||
|
// ==================== Job Events ====================
|
||||||
|
|
||||||
|
/// Persist a job event.
|
||||||
|
async fn save_job_event(
|
||||||
|
&self,
|
||||||
|
job_id: Uuid,
|
||||||
|
event_type: &str,
|
||||||
|
data: &serde_json::Value,
|
||||||
|
) -> Result<(), DatabaseError>;
|
||||||
|
|
||||||
|
/// Load all job events.
|
||||||
|
async fn list_job_events(&self, job_id: Uuid) -> Result<Vec<JobEventRecord>, DatabaseError>;
|
||||||
|
|
||||||
|
// ==================== Routines ====================
|
||||||
|
|
||||||
|
/// Create a new routine.
|
||||||
|
async fn create_routine(&self, routine: &Routine) -> Result<(), DatabaseError>;
|
||||||
|
|
||||||
|
/// Get a routine by ID.
|
||||||
|
async fn get_routine(&self, id: Uuid) -> Result<Option<Routine>, DatabaseError>;
|
||||||
|
|
||||||
|
/// Get a routine by user_id and name.
|
||||||
|
async fn get_routine_by_name(
|
||||||
|
&self,
|
||||||
|
user_id: &str,
|
||||||
|
name: &str,
|
||||||
|
) -> Result<Option<Routine>, DatabaseError>;
|
||||||
|
|
||||||
|
/// List routines for a user.
|
||||||
|
async fn list_routines(&self, user_id: &str) -> Result<Vec<Routine>, DatabaseError>;
|
||||||
|
|
||||||
|
/// List all enabled event routines.
|
||||||
|
async fn list_event_routines(&self) -> Result<Vec<Routine>, DatabaseError>;
|
||||||
|
|
||||||
|
/// List due cron routines.
|
||||||
|
async fn list_due_cron_routines(&self) -> Result<Vec<Routine>, DatabaseError>;
|
||||||
|
|
||||||
|
/// Update a routine.
|
||||||
|
async fn update_routine(&self, routine: &Routine) -> Result<(), DatabaseError>;
|
||||||
|
|
||||||
|
/// Update runtime state after a routine fires.
|
||||||
|
async fn update_routine_runtime(
|
||||||
|
&self,
|
||||||
|
id: Uuid,
|
||||||
|
last_run_at: DateTime<Utc>,
|
||||||
|
next_fire_at: Option<DateTime<Utc>>,
|
||||||
|
run_count: u64,
|
||||||
|
consecutive_failures: u32,
|
||||||
|
state: &serde_json::Value,
|
||||||
|
) -> Result<(), DatabaseError>;
|
||||||
|
|
||||||
|
/// Delete a routine.
|
||||||
|
async fn delete_routine(&self, id: Uuid) -> Result<bool, DatabaseError>;
|
||||||
|
|
||||||
|
// ==================== Routine Runs ====================
|
||||||
|
|
||||||
|
/// Record a routine run starting.
|
||||||
|
async fn create_routine_run(&self, run: &RoutineRun) -> Result<(), DatabaseError>;
|
||||||
|
|
||||||
|
/// Complete a routine run.
|
||||||
|
async fn complete_routine_run(
|
||||||
|
&self,
|
||||||
|
id: Uuid,
|
||||||
|
status: RunStatus,
|
||||||
|
result_summary: Option<&str>,
|
||||||
|
tokens_used: Option<i32>,
|
||||||
|
) -> Result<(), DatabaseError>;
|
||||||
|
|
||||||
|
/// List recent runs for a routine.
|
||||||
|
async fn list_routine_runs(
|
||||||
|
&self,
|
||||||
|
routine_id: Uuid,
|
||||||
|
limit: i64,
|
||||||
|
) -> Result<Vec<RoutineRun>, DatabaseError>;
|
||||||
|
|
||||||
|
/// Count currently running runs for a routine.
|
||||||
|
async fn count_running_routine_runs(&self, routine_id: Uuid) -> Result<i64, DatabaseError>;
|
||||||
|
|
||||||
|
// ==================== Tool Failures ====================
|
||||||
|
|
||||||
|
/// Record a tool failure (upsert).
|
||||||
|
async fn record_tool_failure(
|
||||||
|
&self,
|
||||||
|
tool_name: &str,
|
||||||
|
error_message: &str,
|
||||||
|
) -> Result<(), DatabaseError>;
|
||||||
|
|
||||||
|
/// Get broken tools exceeding threshold.
|
||||||
|
async fn get_broken_tools(&self, threshold: i32) -> Result<Vec<BrokenTool>, DatabaseError>;
|
||||||
|
|
||||||
|
/// Mark a tool as repaired.
|
||||||
|
async fn mark_tool_repaired(&self, tool_name: &str) -> Result<(), DatabaseError>;
|
||||||
|
|
||||||
|
/// Increment repair attempts.
|
||||||
|
async fn increment_repair_attempts(&self, tool_name: &str) -> Result<(), DatabaseError>;
|
||||||
|
|
||||||
|
// ==================== Settings ====================
|
||||||
|
|
||||||
|
/// Get a single setting.
|
||||||
|
async fn get_setting(
|
||||||
|
&self,
|
||||||
|
user_id: &str,
|
||||||
|
key: &str,
|
||||||
|
) -> Result<Option<serde_json::Value>, DatabaseError>;
|
||||||
|
|
||||||
|
/// Get a single setting with metadata.
|
||||||
|
async fn get_setting_full(
|
||||||
|
&self,
|
||||||
|
user_id: &str,
|
||||||
|
key: &str,
|
||||||
|
) -> Result<Option<SettingRow>, DatabaseError>;
|
||||||
|
|
||||||
|
/// Set a single setting (upsert).
|
||||||
|
async fn set_setting(
|
||||||
|
&self,
|
||||||
|
user_id: &str,
|
||||||
|
key: &str,
|
||||||
|
value: &serde_json::Value,
|
||||||
|
) -> Result<(), DatabaseError>;
|
||||||
|
|
||||||
|
/// Delete a single setting.
|
||||||
|
async fn delete_setting(&self, user_id: &str, key: &str) -> Result<bool, DatabaseError>;
|
||||||
|
|
||||||
|
/// List all settings for a user.
|
||||||
|
async fn list_settings(&self, user_id: &str) -> Result<Vec<SettingRow>, DatabaseError>;
|
||||||
|
|
||||||
|
/// Get all settings as a flat map.
|
||||||
|
async fn get_all_settings(
|
||||||
|
&self,
|
||||||
|
user_id: &str,
|
||||||
|
) -> Result<HashMap<String, serde_json::Value>, DatabaseError>;
|
||||||
|
|
||||||
|
/// Bulk-write settings atomically.
|
||||||
|
async fn set_all_settings(
|
||||||
|
&self,
|
||||||
|
user_id: &str,
|
||||||
|
settings: &HashMap<String, serde_json::Value>,
|
||||||
|
) -> Result<(), DatabaseError>;
|
||||||
|
|
||||||
|
/// Check if settings exist for a user.
|
||||||
|
async fn has_settings(&self, user_id: &str) -> Result<bool, DatabaseError>;
|
||||||
|
|
||||||
|
// ==================== Workspace: Documents ====================
|
||||||
|
|
||||||
|
/// Get a document by path.
|
||||||
|
async fn get_document_by_path(
|
||||||
|
&self,
|
||||||
|
user_id: &str,
|
||||||
|
agent_id: Option<Uuid>,
|
||||||
|
path: &str,
|
||||||
|
) -> Result<MemoryDocument, WorkspaceError>;
|
||||||
|
|
||||||
|
/// Get a document by ID.
|
||||||
|
async fn get_document_by_id(&self, id: Uuid) -> Result<MemoryDocument, WorkspaceError>;
|
||||||
|
|
||||||
|
/// Get or create a document by path.
|
||||||
|
async fn get_or_create_document_by_path(
|
||||||
|
&self,
|
||||||
|
user_id: &str,
|
||||||
|
agent_id: Option<Uuid>,
|
||||||
|
path: &str,
|
||||||
|
) -> Result<MemoryDocument, WorkspaceError>;
|
||||||
|
|
||||||
|
/// Update a document's content.
|
||||||
|
async fn update_document(&self, id: Uuid, content: &str) -> Result<(), WorkspaceError>;
|
||||||
|
|
||||||
|
/// Delete a document by path.
|
||||||
|
async fn delete_document_by_path(
|
||||||
|
&self,
|
||||||
|
user_id: &str,
|
||||||
|
agent_id: Option<Uuid>,
|
||||||
|
path: &str,
|
||||||
|
) -> Result<(), WorkspaceError>;
|
||||||
|
|
||||||
|
/// List files and directories in a directory path.
|
||||||
|
async fn list_directory(
|
||||||
|
&self,
|
||||||
|
user_id: &str,
|
||||||
|
agent_id: Option<Uuid>,
|
||||||
|
directory: &str,
|
||||||
|
) -> Result<Vec<WorkspaceEntry>, WorkspaceError>;
|
||||||
|
|
||||||
|
/// List all file paths in the workspace.
|
||||||
|
async fn list_all_paths(
|
||||||
|
&self,
|
||||||
|
user_id: &str,
|
||||||
|
agent_id: Option<Uuid>,
|
||||||
|
) -> Result<Vec<String>, WorkspaceError>;
|
||||||
|
|
||||||
|
/// List all documents for a user.
|
||||||
|
async fn list_documents(
|
||||||
|
&self,
|
||||||
|
user_id: &str,
|
||||||
|
agent_id: Option<Uuid>,
|
||||||
|
) -> Result<Vec<MemoryDocument>, WorkspaceError>;
|
||||||
|
|
||||||
|
// ==================== Workspace: Chunks ====================
|
||||||
|
|
||||||
|
/// Delete all chunks for a document.
|
||||||
|
async fn delete_chunks(&self, document_id: Uuid) -> Result<(), WorkspaceError>;
|
||||||
|
|
||||||
|
/// Insert a chunk.
|
||||||
|
async fn insert_chunk(
|
||||||
|
&self,
|
||||||
|
document_id: Uuid,
|
||||||
|
chunk_index: i32,
|
||||||
|
content: &str,
|
||||||
|
embedding: Option<&[f32]>,
|
||||||
|
) -> Result<Uuid, WorkspaceError>;
|
||||||
|
|
||||||
|
/// Update a chunk's embedding.
|
||||||
|
async fn update_chunk_embedding(
|
||||||
|
&self,
|
||||||
|
chunk_id: Uuid,
|
||||||
|
embedding: &[f32],
|
||||||
|
) -> Result<(), WorkspaceError>;
|
||||||
|
|
||||||
|
/// Get chunks without embeddings for backfilling.
|
||||||
|
async fn get_chunks_without_embeddings(
|
||||||
|
&self,
|
||||||
|
user_id: &str,
|
||||||
|
agent_id: Option<Uuid>,
|
||||||
|
limit: usize,
|
||||||
|
) -> Result<Vec<MemoryChunk>, WorkspaceError>;
|
||||||
|
|
||||||
|
// ==================== Workspace: Search ====================
|
||||||
|
|
||||||
|
/// Perform hybrid search combining FTS and vector similarity.
|
||||||
|
async fn hybrid_search(
|
||||||
|
&self,
|
||||||
|
user_id: &str,
|
||||||
|
agent_id: Option<Uuid>,
|
||||||
|
query: &str,
|
||||||
|
embedding: Option<&[f32]>,
|
||||||
|
config: &SearchConfig,
|
||||||
|
) -> Result<Vec<SearchResult>, WorkspaceError>;
|
||||||
|
}
|
||||||
@@ -0,0 +1,627 @@
|
|||||||
|
//! PostgreSQL backend for the Database trait.
|
||||||
|
//!
|
||||||
|
//! Delegates to the existing `Store` (history) and `Repository` (workspace)
|
||||||
|
//! implementations, avoiding SQL duplication.
|
||||||
|
|
||||||
|
use std::collections::HashMap;
|
||||||
|
|
||||||
|
use async_trait::async_trait;
|
||||||
|
use chrono::{DateTime, Utc};
|
||||||
|
use deadpool_postgres::Pool;
|
||||||
|
use rust_decimal::Decimal;
|
||||||
|
use uuid::Uuid;
|
||||||
|
|
||||||
|
use crate::agent::BrokenTool;
|
||||||
|
use crate::agent::routine::{Routine, RoutineRun, RunStatus};
|
||||||
|
use crate::config::DatabaseConfig;
|
||||||
|
use crate::context::{ActionRecord, JobContext, JobState};
|
||||||
|
use crate::db::Database;
|
||||||
|
use crate::error::{DatabaseError, WorkspaceError};
|
||||||
|
use crate::history::{
|
||||||
|
ConversationMessage, ConversationSummary, JobEventRecord, LlmCallRecord, SandboxJobRecord,
|
||||||
|
SandboxJobSummary, SettingRow, Store,
|
||||||
|
};
|
||||||
|
use crate::workspace::{
|
||||||
|
MemoryChunk, MemoryDocument, Repository, SearchConfig, SearchResult, WorkspaceEntry,
|
||||||
|
};
|
||||||
|
|
||||||
|
/// PostgreSQL database backend.
|
||||||
|
///
|
||||||
|
/// Wraps the existing `Store` (for history/conversations/jobs/routines/settings)
|
||||||
|
/// and `Repository` (for workspace documents/chunks/search) to implement the
|
||||||
|
/// unified `Database` trait.
|
||||||
|
pub struct PgBackend {
|
||||||
|
store: Store,
|
||||||
|
repo: Repository,
|
||||||
|
}
|
||||||
|
|
||||||
|
impl PgBackend {
|
||||||
|
/// Create a new PostgreSQL backend from configuration.
|
||||||
|
pub async fn new(config: &DatabaseConfig) -> Result<Self, DatabaseError> {
|
||||||
|
let store = Store::new(config).await?;
|
||||||
|
let repo = Repository::new(store.pool());
|
||||||
|
Ok(Self { store, repo })
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Get a clone of the connection pool.
|
||||||
|
///
|
||||||
|
/// Useful for sharing with components that still need raw pool access.
|
||||||
|
pub fn pool(&self) -> Pool {
|
||||||
|
self.store.pool()
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
#[async_trait]
|
||||||
|
impl Database for PgBackend {
|
||||||
|
async fn run_migrations(&self) -> Result<(), DatabaseError> {
|
||||||
|
self.store.run_migrations().await
|
||||||
|
}
|
||||||
|
|
||||||
|
// ==================== Conversations ====================
|
||||||
|
|
||||||
|
async fn create_conversation(
|
||||||
|
&self,
|
||||||
|
channel: &str,
|
||||||
|
user_id: &str,
|
||||||
|
thread_id: Option<&str>,
|
||||||
|
) -> Result<Uuid, DatabaseError> {
|
||||||
|
self.store
|
||||||
|
.create_conversation(channel, user_id, thread_id)
|
||||||
|
.await
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn touch_conversation(&self, id: Uuid) -> Result<(), DatabaseError> {
|
||||||
|
self.store.touch_conversation(id).await
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn add_conversation_message(
|
||||||
|
&self,
|
||||||
|
conversation_id: Uuid,
|
||||||
|
role: &str,
|
||||||
|
content: &str,
|
||||||
|
) -> Result<Uuid, DatabaseError> {
|
||||||
|
self.store
|
||||||
|
.add_conversation_message(conversation_id, role, content)
|
||||||
|
.await
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn ensure_conversation(
|
||||||
|
&self,
|
||||||
|
id: Uuid,
|
||||||
|
channel: &str,
|
||||||
|
user_id: &str,
|
||||||
|
thread_id: Option<&str>,
|
||||||
|
) -> Result<(), DatabaseError> {
|
||||||
|
self.store
|
||||||
|
.ensure_conversation(id, channel, user_id, thread_id)
|
||||||
|
.await
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn list_conversations_with_preview(
|
||||||
|
&self,
|
||||||
|
user_id: &str,
|
||||||
|
channel: &str,
|
||||||
|
limit: i64,
|
||||||
|
) -> Result<Vec<ConversationSummary>, DatabaseError> {
|
||||||
|
self.store
|
||||||
|
.list_conversations_with_preview(user_id, channel, limit)
|
||||||
|
.await
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn get_or_create_assistant_conversation(
|
||||||
|
&self,
|
||||||
|
user_id: &str,
|
||||||
|
channel: &str,
|
||||||
|
) -> Result<Uuid, DatabaseError> {
|
||||||
|
self.store
|
||||||
|
.get_or_create_assistant_conversation(user_id, channel)
|
||||||
|
.await
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn create_conversation_with_metadata(
|
||||||
|
&self,
|
||||||
|
channel: &str,
|
||||||
|
user_id: &str,
|
||||||
|
metadata: &serde_json::Value,
|
||||||
|
) -> Result<Uuid, DatabaseError> {
|
||||||
|
self.store
|
||||||
|
.create_conversation_with_metadata(channel, user_id, metadata)
|
||||||
|
.await
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn list_conversation_messages_paginated(
|
||||||
|
&self,
|
||||||
|
conversation_id: Uuid,
|
||||||
|
before: Option<DateTime<Utc>>,
|
||||||
|
limit: i64,
|
||||||
|
) -> Result<(Vec<ConversationMessage>, bool), DatabaseError> {
|
||||||
|
self.store
|
||||||
|
.list_conversation_messages_paginated(conversation_id, before, limit)
|
||||||
|
.await
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn update_conversation_metadata_field(
|
||||||
|
&self,
|
||||||
|
id: Uuid,
|
||||||
|
key: &str,
|
||||||
|
value: &serde_json::Value,
|
||||||
|
) -> Result<(), DatabaseError> {
|
||||||
|
self.store
|
||||||
|
.update_conversation_metadata_field(id, key, value)
|
||||||
|
.await
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn get_conversation_metadata(
|
||||||
|
&self,
|
||||||
|
id: Uuid,
|
||||||
|
) -> Result<Option<serde_json::Value>, DatabaseError> {
|
||||||
|
self.store.get_conversation_metadata(id).await
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn list_conversation_messages(
|
||||||
|
&self,
|
||||||
|
conversation_id: Uuid,
|
||||||
|
) -> Result<Vec<ConversationMessage>, DatabaseError> {
|
||||||
|
self.store.list_conversation_messages(conversation_id).await
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn conversation_belongs_to_user(
|
||||||
|
&self,
|
||||||
|
conversation_id: Uuid,
|
||||||
|
user_id: &str,
|
||||||
|
) -> Result<bool, DatabaseError> {
|
||||||
|
self.store
|
||||||
|
.conversation_belongs_to_user(conversation_id, user_id)
|
||||||
|
.await
|
||||||
|
}
|
||||||
|
|
||||||
|
// ==================== Jobs ====================
|
||||||
|
|
||||||
|
async fn save_job(&self, ctx: &JobContext) -> Result<(), DatabaseError> {
|
||||||
|
self.store.save_job(ctx).await
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn get_job(&self, id: Uuid) -> Result<Option<JobContext>, DatabaseError> {
|
||||||
|
self.store.get_job(id).await
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn update_job_status(
|
||||||
|
&self,
|
||||||
|
id: Uuid,
|
||||||
|
status: JobState,
|
||||||
|
failure_reason: Option<&str>,
|
||||||
|
) -> Result<(), DatabaseError> {
|
||||||
|
self.store
|
||||||
|
.update_job_status(id, status, failure_reason)
|
||||||
|
.await
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn mark_job_stuck(&self, id: Uuid) -> Result<(), DatabaseError> {
|
||||||
|
self.store.mark_job_stuck(id).await
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn get_stuck_jobs(&self) -> Result<Vec<Uuid>, DatabaseError> {
|
||||||
|
self.store.get_stuck_jobs().await
|
||||||
|
}
|
||||||
|
|
||||||
|
// ==================== Actions ====================
|
||||||
|
|
||||||
|
async fn save_action(&self, job_id: Uuid, action: &ActionRecord) -> Result<(), DatabaseError> {
|
||||||
|
self.store.save_action(job_id, action).await
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn get_job_actions(&self, job_id: Uuid) -> Result<Vec<ActionRecord>, DatabaseError> {
|
||||||
|
self.store.get_job_actions(job_id).await
|
||||||
|
}
|
||||||
|
|
||||||
|
// ==================== LLM Calls ====================
|
||||||
|
|
||||||
|
async fn record_llm_call(&self, record: &LlmCallRecord<'_>) -> Result<Uuid, DatabaseError> {
|
||||||
|
self.store.record_llm_call(record).await
|
||||||
|
}
|
||||||
|
|
||||||
|
// ==================== Estimation Snapshots ====================
|
||||||
|
|
||||||
|
async fn save_estimation_snapshot(
|
||||||
|
&self,
|
||||||
|
job_id: Uuid,
|
||||||
|
category: &str,
|
||||||
|
tool_names: &[String],
|
||||||
|
estimated_cost: Decimal,
|
||||||
|
estimated_time_secs: i32,
|
||||||
|
estimated_value: Decimal,
|
||||||
|
) -> Result<Uuid, DatabaseError> {
|
||||||
|
self.store
|
||||||
|
.save_estimation_snapshot(
|
||||||
|
job_id,
|
||||||
|
category,
|
||||||
|
tool_names,
|
||||||
|
estimated_cost,
|
||||||
|
estimated_time_secs,
|
||||||
|
estimated_value,
|
||||||
|
)
|
||||||
|
.await
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn update_estimation_actuals(
|
||||||
|
&self,
|
||||||
|
id: Uuid,
|
||||||
|
actual_cost: Decimal,
|
||||||
|
actual_time_secs: i32,
|
||||||
|
actual_value: Option<Decimal>,
|
||||||
|
) -> Result<(), DatabaseError> {
|
||||||
|
self.store
|
||||||
|
.update_estimation_actuals(id, actual_cost, actual_time_secs, actual_value)
|
||||||
|
.await
|
||||||
|
}
|
||||||
|
|
||||||
|
// ==================== Sandbox Jobs ====================
|
||||||
|
|
||||||
|
async fn save_sandbox_job(&self, job: &SandboxJobRecord) -> Result<(), DatabaseError> {
|
||||||
|
self.store.save_sandbox_job(job).await
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn get_sandbox_job(&self, id: Uuid) -> Result<Option<SandboxJobRecord>, DatabaseError> {
|
||||||
|
self.store.get_sandbox_job(id).await
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn list_sandbox_jobs(&self) -> Result<Vec<SandboxJobRecord>, DatabaseError> {
|
||||||
|
self.store.list_sandbox_jobs().await
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn update_sandbox_job_status(
|
||||||
|
&self,
|
||||||
|
id: Uuid,
|
||||||
|
status: &str,
|
||||||
|
success: Option<bool>,
|
||||||
|
message: Option<&str>,
|
||||||
|
started_at: Option<DateTime<Utc>>,
|
||||||
|
completed_at: Option<DateTime<Utc>>,
|
||||||
|
) -> Result<(), DatabaseError> {
|
||||||
|
self.store
|
||||||
|
.update_sandbox_job_status(id, status, success, message, started_at, completed_at)
|
||||||
|
.await
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn cleanup_stale_sandbox_jobs(&self) -> Result<u64, DatabaseError> {
|
||||||
|
self.store.cleanup_stale_sandbox_jobs().await
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn sandbox_job_summary(&self) -> Result<SandboxJobSummary, DatabaseError> {
|
||||||
|
self.store.sandbox_job_summary().await
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn list_sandbox_jobs_for_user(
|
||||||
|
&self,
|
||||||
|
user_id: &str,
|
||||||
|
) -> Result<Vec<SandboxJobRecord>, DatabaseError> {
|
||||||
|
self.store.list_sandbox_jobs_for_user(user_id).await
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn sandbox_job_summary_for_user(
|
||||||
|
&self,
|
||||||
|
user_id: &str,
|
||||||
|
) -> Result<SandboxJobSummary, DatabaseError> {
|
||||||
|
self.store.sandbox_job_summary_for_user(user_id).await
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn sandbox_job_belongs_to_user(
|
||||||
|
&self,
|
||||||
|
job_id: Uuid,
|
||||||
|
user_id: &str,
|
||||||
|
) -> Result<bool, DatabaseError> {
|
||||||
|
self.store
|
||||||
|
.sandbox_job_belongs_to_user(job_id, user_id)
|
||||||
|
.await
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn update_sandbox_job_mode(&self, id: Uuid, mode: &str) -> Result<(), DatabaseError> {
|
||||||
|
self.store.update_sandbox_job_mode(id, mode).await
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn get_sandbox_job_mode(&self, id: Uuid) -> Result<Option<String>, DatabaseError> {
|
||||||
|
self.store.get_sandbox_job_mode(id).await
|
||||||
|
}
|
||||||
|
|
||||||
|
// ==================== Job Events ====================
|
||||||
|
|
||||||
|
async fn save_job_event(
|
||||||
|
&self,
|
||||||
|
job_id: Uuid,
|
||||||
|
event_type: &str,
|
||||||
|
data: &serde_json::Value,
|
||||||
|
) -> Result<(), DatabaseError> {
|
||||||
|
self.store.save_job_event(job_id, event_type, data).await
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn list_job_events(&self, job_id: Uuid) -> Result<Vec<JobEventRecord>, DatabaseError> {
|
||||||
|
self.store.list_job_events(job_id).await
|
||||||
|
}
|
||||||
|
|
||||||
|
// ==================== Routines ====================
|
||||||
|
|
||||||
|
async fn create_routine(&self, routine: &Routine) -> Result<(), DatabaseError> {
|
||||||
|
self.store.create_routine(routine).await
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn get_routine(&self, id: Uuid) -> Result<Option<Routine>, DatabaseError> {
|
||||||
|
self.store.get_routine(id).await
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn get_routine_by_name(
|
||||||
|
&self,
|
||||||
|
user_id: &str,
|
||||||
|
name: &str,
|
||||||
|
) -> Result<Option<Routine>, DatabaseError> {
|
||||||
|
self.store.get_routine_by_name(user_id, name).await
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn list_routines(&self, user_id: &str) -> Result<Vec<Routine>, DatabaseError> {
|
||||||
|
self.store.list_routines(user_id).await
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn list_event_routines(&self) -> Result<Vec<Routine>, DatabaseError> {
|
||||||
|
self.store.list_event_routines().await
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn list_due_cron_routines(&self) -> Result<Vec<Routine>, DatabaseError> {
|
||||||
|
self.store.list_due_cron_routines().await
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn update_routine(&self, routine: &Routine) -> Result<(), DatabaseError> {
|
||||||
|
self.store.update_routine(routine).await
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn update_routine_runtime(
|
||||||
|
&self,
|
||||||
|
id: Uuid,
|
||||||
|
last_run_at: DateTime<Utc>,
|
||||||
|
next_fire_at: Option<DateTime<Utc>>,
|
||||||
|
run_count: u64,
|
||||||
|
consecutive_failures: u32,
|
||||||
|
state: &serde_json::Value,
|
||||||
|
) -> Result<(), DatabaseError> {
|
||||||
|
self.store
|
||||||
|
.update_routine_runtime(
|
||||||
|
id,
|
||||||
|
last_run_at,
|
||||||
|
next_fire_at,
|
||||||
|
run_count,
|
||||||
|
consecutive_failures,
|
||||||
|
state,
|
||||||
|
)
|
||||||
|
.await
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn delete_routine(&self, id: Uuid) -> Result<bool, DatabaseError> {
|
||||||
|
self.store.delete_routine(id).await
|
||||||
|
}
|
||||||
|
|
||||||
|
// ==================== Routine Runs ====================
|
||||||
|
|
||||||
|
async fn create_routine_run(&self, run: &RoutineRun) -> Result<(), DatabaseError> {
|
||||||
|
self.store.create_routine_run(run).await
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn complete_routine_run(
|
||||||
|
&self,
|
||||||
|
id: Uuid,
|
||||||
|
status: RunStatus,
|
||||||
|
result_summary: Option<&str>,
|
||||||
|
tokens_used: Option<i32>,
|
||||||
|
) -> Result<(), DatabaseError> {
|
||||||
|
self.store
|
||||||
|
.complete_routine_run(id, status, result_summary, tokens_used)
|
||||||
|
.await
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn list_routine_runs(
|
||||||
|
&self,
|
||||||
|
routine_id: Uuid,
|
||||||
|
limit: i64,
|
||||||
|
) -> Result<Vec<RoutineRun>, DatabaseError> {
|
||||||
|
self.store.list_routine_runs(routine_id, limit).await
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn count_running_routine_runs(&self, routine_id: Uuid) -> Result<i64, DatabaseError> {
|
||||||
|
self.store.count_running_routine_runs(routine_id).await
|
||||||
|
}
|
||||||
|
|
||||||
|
// ==================== Tool Failures ====================
|
||||||
|
|
||||||
|
async fn record_tool_failure(
|
||||||
|
&self,
|
||||||
|
tool_name: &str,
|
||||||
|
error_message: &str,
|
||||||
|
) -> Result<(), DatabaseError> {
|
||||||
|
self.store
|
||||||
|
.record_tool_failure(tool_name, error_message)
|
||||||
|
.await
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn get_broken_tools(&self, threshold: i32) -> Result<Vec<BrokenTool>, DatabaseError> {
|
||||||
|
self.store.get_broken_tools(threshold).await
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn mark_tool_repaired(&self, tool_name: &str) -> Result<(), DatabaseError> {
|
||||||
|
self.store.mark_tool_repaired(tool_name).await
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn increment_repair_attempts(&self, tool_name: &str) -> Result<(), DatabaseError> {
|
||||||
|
self.store.increment_repair_attempts(tool_name).await
|
||||||
|
}
|
||||||
|
|
||||||
|
// ==================== Settings ====================
|
||||||
|
|
||||||
|
async fn get_setting(
|
||||||
|
&self,
|
||||||
|
user_id: &str,
|
||||||
|
key: &str,
|
||||||
|
) -> Result<Option<serde_json::Value>, DatabaseError> {
|
||||||
|
self.store.get_setting(user_id, key).await
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn get_setting_full(
|
||||||
|
&self,
|
||||||
|
user_id: &str,
|
||||||
|
key: &str,
|
||||||
|
) -> Result<Option<SettingRow>, DatabaseError> {
|
||||||
|
self.store.get_setting_full(user_id, key).await
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn set_setting(
|
||||||
|
&self,
|
||||||
|
user_id: &str,
|
||||||
|
key: &str,
|
||||||
|
value: &serde_json::Value,
|
||||||
|
) -> Result<(), DatabaseError> {
|
||||||
|
self.store.set_setting(user_id, key, value).await
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn delete_setting(&self, user_id: &str, key: &str) -> Result<bool, DatabaseError> {
|
||||||
|
self.store.delete_setting(user_id, key).await
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn list_settings(&self, user_id: &str) -> Result<Vec<SettingRow>, DatabaseError> {
|
||||||
|
self.store.list_settings(user_id).await
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn get_all_settings(
|
||||||
|
&self,
|
||||||
|
user_id: &str,
|
||||||
|
) -> Result<HashMap<String, serde_json::Value>, DatabaseError> {
|
||||||
|
self.store.get_all_settings(user_id).await
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn set_all_settings(
|
||||||
|
&self,
|
||||||
|
user_id: &str,
|
||||||
|
settings: &HashMap<String, serde_json::Value>,
|
||||||
|
) -> Result<(), DatabaseError> {
|
||||||
|
self.store.set_all_settings(user_id, settings).await
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn has_settings(&self, user_id: &str) -> Result<bool, DatabaseError> {
|
||||||
|
self.store.has_settings(user_id).await
|
||||||
|
}
|
||||||
|
|
||||||
|
// ==================== Workspace: Documents ====================
|
||||||
|
|
||||||
|
async fn get_document_by_path(
|
||||||
|
&self,
|
||||||
|
user_id: &str,
|
||||||
|
agent_id: Option<Uuid>,
|
||||||
|
path: &str,
|
||||||
|
) -> Result<MemoryDocument, WorkspaceError> {
|
||||||
|
self.repo
|
||||||
|
.get_document_by_path(user_id, agent_id, path)
|
||||||
|
.await
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn get_document_by_id(&self, id: Uuid) -> Result<MemoryDocument, WorkspaceError> {
|
||||||
|
self.repo.get_document_by_id(id).await
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn get_or_create_document_by_path(
|
||||||
|
&self,
|
||||||
|
user_id: &str,
|
||||||
|
agent_id: Option<Uuid>,
|
||||||
|
path: &str,
|
||||||
|
) -> Result<MemoryDocument, WorkspaceError> {
|
||||||
|
self.repo
|
||||||
|
.get_or_create_document_by_path(user_id, agent_id, path)
|
||||||
|
.await
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn update_document(&self, id: Uuid, content: &str) -> Result<(), WorkspaceError> {
|
||||||
|
self.repo.update_document(id, content).await
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn delete_document_by_path(
|
||||||
|
&self,
|
||||||
|
user_id: &str,
|
||||||
|
agent_id: Option<Uuid>,
|
||||||
|
path: &str,
|
||||||
|
) -> Result<(), WorkspaceError> {
|
||||||
|
self.repo
|
||||||
|
.delete_document_by_path(user_id, agent_id, path)
|
||||||
|
.await
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn list_directory(
|
||||||
|
&self,
|
||||||
|
user_id: &str,
|
||||||
|
agent_id: Option<Uuid>,
|
||||||
|
directory: &str,
|
||||||
|
) -> Result<Vec<WorkspaceEntry>, WorkspaceError> {
|
||||||
|
self.repo.list_directory(user_id, agent_id, directory).await
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn list_all_paths(
|
||||||
|
&self,
|
||||||
|
user_id: &str,
|
||||||
|
agent_id: Option<Uuid>,
|
||||||
|
) -> Result<Vec<String>, WorkspaceError> {
|
||||||
|
self.repo.list_all_paths(user_id, agent_id).await
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn list_documents(
|
||||||
|
&self,
|
||||||
|
user_id: &str,
|
||||||
|
agent_id: Option<Uuid>,
|
||||||
|
) -> Result<Vec<MemoryDocument>, WorkspaceError> {
|
||||||
|
self.repo.list_documents(user_id, agent_id).await
|
||||||
|
}
|
||||||
|
|
||||||
|
// ==================== Workspace: Chunks ====================
|
||||||
|
|
||||||
|
async fn delete_chunks(&self, document_id: Uuid) -> Result<(), WorkspaceError> {
|
||||||
|
self.repo.delete_chunks(document_id).await
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn insert_chunk(
|
||||||
|
&self,
|
||||||
|
document_id: Uuid,
|
||||||
|
chunk_index: i32,
|
||||||
|
content: &str,
|
||||||
|
embedding: Option<&[f32]>,
|
||||||
|
) -> Result<Uuid, WorkspaceError> {
|
||||||
|
self.repo
|
||||||
|
.insert_chunk(document_id, chunk_index, content, embedding)
|
||||||
|
.await
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn update_chunk_embedding(
|
||||||
|
&self,
|
||||||
|
chunk_id: Uuid,
|
||||||
|
embedding: &[f32],
|
||||||
|
) -> Result<(), WorkspaceError> {
|
||||||
|
self.repo.update_chunk_embedding(chunk_id, embedding).await
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn get_chunks_without_embeddings(
|
||||||
|
&self,
|
||||||
|
user_id: &str,
|
||||||
|
agent_id: Option<Uuid>,
|
||||||
|
limit: usize,
|
||||||
|
) -> Result<Vec<MemoryChunk>, WorkspaceError> {
|
||||||
|
self.repo
|
||||||
|
.get_chunks_without_embeddings(user_id, agent_id, limit)
|
||||||
|
.await
|
||||||
|
}
|
||||||
|
|
||||||
|
// ==================== Workspace: Search ====================
|
||||||
|
|
||||||
|
async fn hybrid_search(
|
||||||
|
&self,
|
||||||
|
user_id: &str,
|
||||||
|
agent_id: Option<Uuid>,
|
||||||
|
query: &str,
|
||||||
|
embedding: Option<&[f32]>,
|
||||||
|
config: &SearchConfig,
|
||||||
|
) -> Result<Vec<SearchResult>, WorkspaceError> {
|
||||||
|
self.repo
|
||||||
|
.hybrid_search(user_id, agent_id, query, embedding, config)
|
||||||
|
.await
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -39,6 +39,12 @@ pub enum Error {
|
|||||||
|
|
||||||
#[error("Workspace error: {0}")]
|
#[error("Workspace error: {0}")]
|
||||||
Workspace(#[from] WorkspaceError),
|
Workspace(#[from] WorkspaceError),
|
||||||
|
|
||||||
|
#[error("Orchestrator error: {0}")]
|
||||||
|
Orchestrator(#[from] OrchestratorError),
|
||||||
|
|
||||||
|
#[error("Worker error: {0}")]
|
||||||
|
Worker(#[from] WorkerError),
|
||||||
}
|
}
|
||||||
|
|
||||||
/// Configuration-related errors.
|
/// Configuration-related errors.
|
||||||
@@ -81,14 +87,21 @@ pub enum DatabaseError {
|
|||||||
#[error("Serialization error: {0}")]
|
#[error("Serialization error: {0}")]
|
||||||
Serialization(String),
|
Serialization(String),
|
||||||
|
|
||||||
|
#[cfg(feature = "postgres")]
|
||||||
#[error("PostgreSQL error: {0}")]
|
#[error("PostgreSQL error: {0}")]
|
||||||
Postgres(#[from] tokio_postgres::Error),
|
Postgres(#[from] tokio_postgres::Error),
|
||||||
|
|
||||||
|
#[cfg(feature = "postgres")]
|
||||||
#[error("Pool build error: {0}")]
|
#[error("Pool build error: {0}")]
|
||||||
PoolBuild(#[from] deadpool_postgres::BuildError),
|
PoolBuild(#[from] deadpool_postgres::BuildError),
|
||||||
|
|
||||||
|
#[cfg(feature = "postgres")]
|
||||||
#[error("Pool runtime error: {0}")]
|
#[error("Pool runtime error: {0}")]
|
||||||
PoolRuntime(#[from] deadpool_postgres::PoolError),
|
PoolRuntime(#[from] deadpool_postgres::PoolError),
|
||||||
|
|
||||||
|
#[cfg(feature = "libsql")]
|
||||||
|
#[error("LibSQL error: {0}")]
|
||||||
|
LibSql(#[from] libsql::Error),
|
||||||
}
|
}
|
||||||
|
|
||||||
/// Channel-related errors.
|
/// Channel-related errors.
|
||||||
@@ -308,5 +321,52 @@ pub enum WorkspaceError {
|
|||||||
HeartbeatError { reason: String },
|
HeartbeatError { reason: String },
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/// Orchestrator errors (internal API, container management).
|
||||||
|
#[derive(Debug, thiserror::Error)]
|
||||||
|
pub enum OrchestratorError {
|
||||||
|
#[error("Container creation failed for job {job_id}: {reason}")]
|
||||||
|
ContainerCreationFailed { job_id: Uuid, reason: String },
|
||||||
|
|
||||||
|
#[error("Container not found for job {job_id}")]
|
||||||
|
ContainerNotFound { job_id: Uuid },
|
||||||
|
|
||||||
|
#[error("Container for job {job_id} is in unexpected state: {state}")]
|
||||||
|
InvalidContainerState { job_id: Uuid, state: String },
|
||||||
|
|
||||||
|
#[error("Worker authentication failed: {reason}")]
|
||||||
|
AuthFailed { reason: String },
|
||||||
|
|
||||||
|
#[error("Internal API error: {reason}")]
|
||||||
|
ApiError { reason: String },
|
||||||
|
|
||||||
|
#[error("Docker error: {reason}")]
|
||||||
|
Docker { reason: String },
|
||||||
|
|
||||||
|
#[error("Job {job_id} timed out in container")]
|
||||||
|
ContainerTimeout { job_id: Uuid },
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Worker errors (container-side execution).
|
||||||
|
#[derive(Debug, thiserror::Error)]
|
||||||
|
pub enum WorkerError {
|
||||||
|
#[error("Failed to connect to orchestrator at {url}: {reason}")]
|
||||||
|
ConnectionFailed { url: String, reason: String },
|
||||||
|
|
||||||
|
#[error("LLM proxy request failed: {reason}")]
|
||||||
|
LlmProxyFailed { reason: String },
|
||||||
|
|
||||||
|
#[error("Secret resolution failed for {secret_name}: {reason}")]
|
||||||
|
SecretResolveFailed { secret_name: String, reason: String },
|
||||||
|
|
||||||
|
#[error("Orchestrator returned error for job {job_id}: {reason}")]
|
||||||
|
OrchestratorRejected { job_id: Uuid, reason: String },
|
||||||
|
|
||||||
|
#[error("Worker execution failed: {reason}")]
|
||||||
|
ExecutionFailed { reason: String },
|
||||||
|
|
||||||
|
#[error("Missing worker token (IRONCLAW_WORKER_TOKEN not set)")]
|
||||||
|
MissingToken,
|
||||||
|
}
|
||||||
|
|
||||||
/// Result type alias for the agent.
|
/// Result type alias for the agent.
|
||||||
pub type Result<T> = std::result::Result<T, Error>;
|
pub type Result<T> = std::result::Result<T, Error>;
|
||||||
|
|||||||
@@ -20,10 +20,6 @@ impl CostEstimator {
|
|||||||
|
|
||||||
// Default tool costs (in USD or equivalent)
|
// Default tool costs (in USD or equivalent)
|
||||||
tool_costs.insert("http".to_string(), dec!(0.0001)); // API call
|
tool_costs.insert("http".to_string(), dec!(0.0001)); // API call
|
||||||
tool_costs.insert("marketplace".to_string(), dec!(0.01)); // Gas costs
|
|
||||||
tool_costs.insert("ecommerce".to_string(), dec!(0.001)); // API call
|
|
||||||
tool_costs.insert("taskrabbit".to_string(), dec!(0.0)); // Cost comes from task itself
|
|
||||||
tool_costs.insert("restaurant".to_string(), dec!(0.001)); // API call
|
|
||||||
tool_costs.insert("echo".to_string(), dec!(0.0)); // Free
|
tool_costs.insert("echo".to_string(), dec!(0.0)); // Free
|
||||||
tool_costs.insert("time".to_string(), dec!(0.0)); // Free
|
tool_costs.insert("time".to_string(), dec!(0.0)); // Free
|
||||||
tool_costs.insert("json".to_string(), dec!(0.0)); // Free
|
tool_costs.insert("json".to_string(), dec!(0.0)); // Free
|
||||||
@@ -74,7 +70,7 @@ mod tests {
|
|||||||
let estimator = CostEstimator::new();
|
let estimator = CostEstimator::new();
|
||||||
|
|
||||||
assert_eq!(estimator.estimate_tool("echo"), dec!(0.0));
|
assert_eq!(estimator.estimate_tool("echo"), dec!(0.0));
|
||||||
assert_eq!(estimator.estimate_tool("marketplace"), dec!(0.01));
|
assert_eq!(estimator.estimate_tool("http"), dec!(0.0001));
|
||||||
assert!(estimator.estimate_tool("unknown") > dec!(0.0));
|
assert!(estimator.estimate_tool("unknown") > dec!(0.0));
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -16,10 +16,6 @@ impl TimeEstimator {
|
|||||||
|
|
||||||
// Default tool durations
|
// Default tool durations
|
||||||
tool_durations.insert("http".to_string(), Duration::from_secs(5));
|
tool_durations.insert("http".to_string(), Duration::from_secs(5));
|
||||||
tool_durations.insert("marketplace".to_string(), Duration::from_secs(10));
|
|
||||||
tool_durations.insert("ecommerce".to_string(), Duration::from_secs(8));
|
|
||||||
tool_durations.insert("taskrabbit".to_string(), Duration::from_secs(30)); // Just API, not task itself
|
|
||||||
tool_durations.insert("restaurant".to_string(), Duration::from_secs(5));
|
|
||||||
tool_durations.insert("echo".to_string(), Duration::from_millis(10));
|
tool_durations.insert("echo".to_string(), Duration::from_millis(10));
|
||||||
tool_durations.insert("time".to_string(), Duration::from_millis(1));
|
tool_durations.insert("time".to_string(), Duration::from_millis(1));
|
||||||
tool_durations.insert("json".to_string(), Duration::from_millis(5));
|
tool_durations.insert("json".to_string(), Duration::from_millis(5));
|
||||||
|
|||||||
@@ -144,14 +144,13 @@ impl SuccessEvaluator for RuleBasedEvaluator {
|
|||||||
|
|
||||||
// Check for critical errors
|
// Check for critical errors
|
||||||
for action in actions.iter().filter(|a| !a.success) {
|
for action in actions.iter().filter(|a| !a.success) {
|
||||||
if let Some(ref error) = action.error {
|
if let Some(ref error) = action.error
|
||||||
if error.to_lowercase().contains("critical")
|
&& (error.to_lowercase().contains("critical")
|
||||||
|| error.to_lowercase().contains("fatal")
|
|| error.to_lowercase().contains("fatal"))
|
||||||
{
|
{
|
||||||
issues.push(format!("Critical error in {}: {}", action.tool_name, error));
|
issues.push(format!("Critical error in {}: {}", action.tool_name, error));
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
|
||||||
|
|
||||||
// Check job state
|
// Check job state
|
||||||
if job.state != crate::context::JobState::Completed
|
if job.state != crate::context::JobState::Completed
|
||||||
|
|||||||
+106
-17
@@ -23,9 +23,7 @@ use crate::tools::mcp::auth::{
|
|||||||
PkceChallenge, authorize_mcp_server, build_authorization_url, discover_full_oauth_metadata,
|
PkceChallenge, authorize_mcp_server, build_authorization_url, discover_full_oauth_metadata,
|
||||||
find_available_port, is_authenticated, register_client,
|
find_available_port, is_authenticated, register_client,
|
||||||
};
|
};
|
||||||
use crate::tools::mcp::config::{
|
use crate::tools::mcp::config::McpServerConfig;
|
||||||
McpServerConfig, add_mcp_server, get_mcp_server, load_mcp_servers, remove_mcp_server,
|
|
||||||
};
|
|
||||||
use crate::tools::mcp::session::McpSessionManager;
|
use crate::tools::mcp::session::McpSessionManager;
|
||||||
use crate::tools::wasm::{WasmToolLoader, WasmToolRuntime, discover_tools};
|
use crate::tools::wasm::{WasmToolLoader, WasmToolRuntime, discover_tools};
|
||||||
|
|
||||||
@@ -58,6 +56,8 @@ pub struct ExtensionManager {
|
|||||||
/// Tunnel URL for remote OAuth callbacks (used in future iterations).
|
/// Tunnel URL for remote OAuth callbacks (used in future iterations).
|
||||||
_tunnel_url: Option<String>,
|
_tunnel_url: Option<String>,
|
||||||
user_id: String,
|
user_id: String,
|
||||||
|
/// Optional database store for DB-backed MCP config.
|
||||||
|
store: Option<Arc<dyn crate::db::Database>>,
|
||||||
}
|
}
|
||||||
|
|
||||||
impl ExtensionManager {
|
impl ExtensionManager {
|
||||||
@@ -71,6 +71,7 @@ impl ExtensionManager {
|
|||||||
wasm_channels_dir: PathBuf,
|
wasm_channels_dir: PathBuf,
|
||||||
tunnel_url: Option<String>,
|
tunnel_url: Option<String>,
|
||||||
user_id: String,
|
user_id: String,
|
||||||
|
store: Option<Arc<dyn crate::db::Database>>,
|
||||||
) -> Self {
|
) -> Self {
|
||||||
Self {
|
Self {
|
||||||
registry: ExtensionRegistry::new(),
|
registry: ExtensionRegistry::new(),
|
||||||
@@ -85,6 +86,7 @@ impl ExtensionManager {
|
|||||||
pending_auth: RwLock::new(HashMap::new()),
|
pending_auth: RwLock::new(HashMap::new()),
|
||||||
_tunnel_url: tunnel_url,
|
_tunnel_url: tunnel_url,
|
||||||
user_id,
|
user_id,
|
||||||
|
store,
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -191,7 +193,7 @@ impl ExtensionManager {
|
|||||||
|
|
||||||
// List MCP servers
|
// List MCP servers
|
||||||
if kind_filter.is_none() || kind_filter == Some(ExtensionKind::McpServer) {
|
if kind_filter.is_none() || kind_filter == Some(ExtensionKind::McpServer) {
|
||||||
match load_mcp_servers().await {
|
match self.load_mcp_servers().await {
|
||||||
Ok(servers) => {
|
Ok(servers) => {
|
||||||
for server in &servers.servers {
|
for server in &servers.servers {
|
||||||
let authenticated =
|
let authenticated =
|
||||||
@@ -304,7 +306,7 @@ impl ExtensionManager {
|
|||||||
self.mcp_clients.write().await.remove(name);
|
self.mcp_clients.write().await.remove(name);
|
||||||
|
|
||||||
// Remove from config
|
// Remove from config
|
||||||
remove_mcp_server(name)
|
self.remove_mcp_server(name)
|
||||||
.await
|
.await
|
||||||
.map_err(|e| ExtensionError::Config(e.to_string()))?;
|
.map_err(|e| ExtensionError::Config(e.to_string()))?;
|
||||||
|
|
||||||
@@ -342,6 +344,56 @@ impl ExtensionManager {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// ── MCP config helpers (DB with disk fallback) ─────────────────────
|
||||||
|
|
||||||
|
async fn load_mcp_servers(
|
||||||
|
&self,
|
||||||
|
) -> Result<crate::tools::mcp::config::McpServersFile, crate::tools::mcp::config::ConfigError>
|
||||||
|
{
|
||||||
|
if let Some(ref store) = self.store {
|
||||||
|
crate::tools::mcp::config::load_mcp_servers_from_db(store.as_ref(), &self.user_id).await
|
||||||
|
} else {
|
||||||
|
crate::tools::mcp::config::load_mcp_servers().await
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn get_mcp_server(
|
||||||
|
&self,
|
||||||
|
name: &str,
|
||||||
|
) -> Result<McpServerConfig, crate::tools::mcp::config::ConfigError> {
|
||||||
|
let servers = self.load_mcp_servers().await?;
|
||||||
|
servers.get(name).cloned().ok_or_else(|| {
|
||||||
|
crate::tools::mcp::config::ConfigError::ServerNotFound {
|
||||||
|
name: name.to_string(),
|
||||||
|
}
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn add_mcp_server(
|
||||||
|
&self,
|
||||||
|
config: McpServerConfig,
|
||||||
|
) -> Result<(), crate::tools::mcp::config::ConfigError> {
|
||||||
|
config.validate()?;
|
||||||
|
if let Some(ref store) = self.store {
|
||||||
|
crate::tools::mcp::config::add_mcp_server_db(store.as_ref(), &self.user_id, config)
|
||||||
|
.await
|
||||||
|
} else {
|
||||||
|
crate::tools::mcp::config::add_mcp_server(config).await
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn remove_mcp_server(
|
||||||
|
&self,
|
||||||
|
name: &str,
|
||||||
|
) -> Result<(), crate::tools::mcp::config::ConfigError> {
|
||||||
|
if let Some(ref store) = self.store {
|
||||||
|
crate::tools::mcp::config::remove_mcp_server_db(store.as_ref(), &self.user_id, name)
|
||||||
|
.await
|
||||||
|
} else {
|
||||||
|
crate::tools::mcp::config::remove_mcp_server(name).await
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
// ── Private helpers ──────────────────────────────────────────────────
|
// ── Private helpers ──────────────────────────────────────────────────
|
||||||
|
|
||||||
async fn install_from_entry(
|
async fn install_from_entry(
|
||||||
@@ -381,7 +433,7 @@ impl ExtensionManager {
|
|||||||
url: &str,
|
url: &str,
|
||||||
) -> Result<InstallResult, ExtensionError> {
|
) -> Result<InstallResult, ExtensionError> {
|
||||||
// Check if already installed
|
// Check if already installed
|
||||||
if get_mcp_server(name).await.is_ok() {
|
if self.get_mcp_server(name).await.is_ok() {
|
||||||
return Err(ExtensionError::AlreadyInstalled(name.to_string()));
|
return Err(ExtensionError::AlreadyInstalled(name.to_string()));
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -390,7 +442,7 @@ impl ExtensionManager {
|
|||||||
.validate()
|
.validate()
|
||||||
.map_err(|e| ExtensionError::InvalidUrl(e.to_string()))?;
|
.map_err(|e| ExtensionError::InvalidUrl(e.to_string()))?;
|
||||||
|
|
||||||
add_mcp_server(config)
|
self.add_mcp_server(config)
|
||||||
.await
|
.await
|
||||||
.map_err(|e| ExtensionError::Config(e.to_string()))?;
|
.map_err(|e| ExtensionError::Config(e.to_string()))?;
|
||||||
|
|
||||||
@@ -411,7 +463,16 @@ impl ExtensionManager {
|
|||||||
name: &str,
|
name: &str,
|
||||||
url: &str,
|
url: &str,
|
||||||
) -> Result<InstallResult, ExtensionError> {
|
) -> Result<InstallResult, ExtensionError> {
|
||||||
// Download the WASM binary
|
// Require HTTPS to prevent downgrade attacks
|
||||||
|
if !url.starts_with("https://") {
|
||||||
|
return Err(ExtensionError::InstallFailed(
|
||||||
|
"Only HTTPS URLs are allowed for extension downloads".to_string(),
|
||||||
|
));
|
||||||
|
}
|
||||||
|
|
||||||
|
// 50 MB cap to prevent disk-fill DoS
|
||||||
|
const MAX_WASM_SIZE: usize = 50 * 1024 * 1024;
|
||||||
|
|
||||||
let client = reqwest::Client::builder()
|
let client = reqwest::Client::builder()
|
||||||
.timeout(std::time::Duration::from_secs(60))
|
.timeout(std::time::Duration::from_secs(60))
|
||||||
.build()
|
.build()
|
||||||
@@ -430,11 +491,36 @@ impl ExtensionManager {
|
|||||||
)));
|
)));
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Check Content-Length header before downloading the full body
|
||||||
|
if let Some(len) = response.content_length()
|
||||||
|
&& len as usize > MAX_WASM_SIZE
|
||||||
|
{
|
||||||
|
return Err(ExtensionError::InstallFailed(format!(
|
||||||
|
"WASM binary too large ({} bytes, max {} bytes)",
|
||||||
|
len, MAX_WASM_SIZE
|
||||||
|
)));
|
||||||
|
}
|
||||||
|
|
||||||
let bytes = response
|
let bytes = response
|
||||||
.bytes()
|
.bytes()
|
||||||
.await
|
.await
|
||||||
.map_err(|e| ExtensionError::DownloadFailed(e.to_string()))?;
|
.map_err(|e| ExtensionError::DownloadFailed(e.to_string()))?;
|
||||||
|
|
||||||
|
if bytes.len() > MAX_WASM_SIZE {
|
||||||
|
return Err(ExtensionError::InstallFailed(format!(
|
||||||
|
"WASM binary too large ({} bytes, max {} bytes)",
|
||||||
|
bytes.len(),
|
||||||
|
MAX_WASM_SIZE
|
||||||
|
)));
|
||||||
|
}
|
||||||
|
|
||||||
|
// Basic WASM magic number check (\0asm)
|
||||||
|
if bytes.len() < 4 || &bytes[..4] != b"\0asm" {
|
||||||
|
return Err(ExtensionError::InstallFailed(
|
||||||
|
"Downloaded file is not a valid WASM binary (bad magic number)".to_string(),
|
||||||
|
));
|
||||||
|
}
|
||||||
|
|
||||||
// Ensure tools directory exists
|
// Ensure tools directory exists
|
||||||
tokio::fs::create_dir_all(&self.wasm_tools_dir)
|
tokio::fs::create_dir_all(&self.wasm_tools_dir)
|
||||||
.await
|
.await
|
||||||
@@ -447,9 +533,10 @@ impl ExtensionManager {
|
|||||||
.map_err(|e| ExtensionError::InstallFailed(e.to_string()))?;
|
.map_err(|e| ExtensionError::InstallFailed(e.to_string()))?;
|
||||||
|
|
||||||
tracing::info!(
|
tracing::info!(
|
||||||
"Installed WASM tool '{}' ({} bytes) to {}",
|
"Installed WASM tool '{}' ({} bytes) from {} to {}",
|
||||||
name,
|
name,
|
||||||
bytes.len(),
|
bytes.len(),
|
||||||
|
url,
|
||||||
wasm_path.display()
|
wasm_path.display()
|
||||||
);
|
);
|
||||||
|
|
||||||
@@ -465,7 +552,8 @@ impl ExtensionManager {
|
|||||||
name: &str,
|
name: &str,
|
||||||
token: Option<&str>,
|
token: Option<&str>,
|
||||||
) -> Result<AuthResult, ExtensionError> {
|
) -> Result<AuthResult, ExtensionError> {
|
||||||
let server = get_mcp_server(name)
|
let server = self
|
||||||
|
.get_mcp_server(name)
|
||||||
.await
|
.await
|
||||||
.map_err(|e| ExtensionError::NotInstalled(e.to_string()))?;
|
.map_err(|e| ExtensionError::NotInstalled(e.to_string()))?;
|
||||||
|
|
||||||
@@ -680,11 +768,12 @@ impl ExtensionManager {
|
|||||||
};
|
};
|
||||||
|
|
||||||
// Check env var first
|
// Check env var first
|
||||||
if let Some(ref env_var) = auth.env_var {
|
if let Some(ref env_var) = auth.env_var
|
||||||
if let Ok(value) = std::env::var(env_var) {
|
&& let Ok(value) = std::env::var(env_var)
|
||||||
|
{
|
||||||
// Store the env var value as a secret
|
// Store the env var value as a secret
|
||||||
let params = CreateSecretParams::new(&auth.secret_name, &value)
|
let params =
|
||||||
.with_provider(name.to_string());
|
CreateSecretParams::new(&auth.secret_name, &value).with_provider(name.to_string());
|
||||||
self.secrets
|
self.secrets
|
||||||
.create(&self.user_id, params)
|
.create(&self.user_id, params)
|
||||||
.await
|
.await
|
||||||
@@ -701,7 +790,6 @@ impl ExtensionManager {
|
|||||||
status: "authenticated".to_string(),
|
status: "authenticated".to_string(),
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
}
|
|
||||||
|
|
||||||
// Check if already authenticated
|
// Check if already authenticated
|
||||||
if self
|
if self
|
||||||
@@ -784,7 +872,8 @@ impl ExtensionManager {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
let server = get_mcp_server(name)
|
let server = self
|
||||||
|
.get_mcp_server(name)
|
||||||
.await
|
.await
|
||||||
.map_err(|e| ExtensionError::NotInstalled(e.to_string()))?;
|
.map_err(|e| ExtensionError::NotInstalled(e.to_string()))?;
|
||||||
|
|
||||||
@@ -893,7 +982,7 @@ impl ExtensionManager {
|
|||||||
/// Determine what kind of installed extension this is.
|
/// Determine what kind of installed extension this is.
|
||||||
async fn determine_installed_kind(&self, name: &str) -> Result<ExtensionKind, ExtensionError> {
|
async fn determine_installed_kind(&self, name: &str) -> Result<ExtensionKind, ExtensionError> {
|
||||||
// Check MCP servers first
|
// Check MCP servers first
|
||||||
if get_mcp_server(name).await.is_ok() {
|
if self.get_mcp_server(name).await.is_ok() {
|
||||||
return Ok(ExtensionKind::McpServer);
|
return Ok(ExtensionKind::McpServer);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
+8
-1
@@ -5,8 +5,15 @@
|
|||||||
//! - Learning from past executions
|
//! - Learning from past executions
|
||||||
//! - Analytics and metrics
|
//! - Analytics and metrics
|
||||||
|
|
||||||
|
#[cfg(feature = "postgres")]
|
||||||
mod analytics;
|
mod analytics;
|
||||||
mod store;
|
mod store;
|
||||||
|
|
||||||
|
#[cfg(feature = "postgres")]
|
||||||
pub use analytics::{JobStats, ToolStats};
|
pub use analytics::{JobStats, ToolStats};
|
||||||
pub use store::{LlmCallRecord, Store};
|
#[cfg(feature = "postgres")]
|
||||||
|
pub use store::Store;
|
||||||
|
pub use store::{
|
||||||
|
ConversationMessage, ConversationSummary, JobEventRecord, LlmCallRecord, SandboxJobRecord,
|
||||||
|
SandboxJobSummary, SettingRow,
|
||||||
|
};
|
||||||
|
|||||||
+1247
-6
File diff suppressed because it is too large
Load Diff
@@ -39,22 +39,29 @@
|
|||||||
//! - **Continuous learning** - Improve estimates from historical data
|
//! - **Continuous learning** - Improve estimates from historical data
|
||||||
|
|
||||||
pub mod agent;
|
pub mod agent;
|
||||||
|
pub mod bootstrap;
|
||||||
pub mod channels;
|
pub mod channels;
|
||||||
pub mod cli;
|
pub mod cli;
|
||||||
pub mod config;
|
pub mod config;
|
||||||
pub mod context;
|
pub mod context;
|
||||||
|
pub mod db;
|
||||||
pub mod error;
|
pub mod error;
|
||||||
pub mod estimation;
|
pub mod estimation;
|
||||||
pub mod evaluation;
|
pub mod evaluation;
|
||||||
pub mod extensions;
|
pub mod extensions;
|
||||||
pub mod history;
|
pub mod history;
|
||||||
pub mod llm;
|
pub mod llm;
|
||||||
|
pub mod orchestrator;
|
||||||
|
pub mod pairing;
|
||||||
pub mod safety;
|
pub mod safety;
|
||||||
pub mod sandbox;
|
pub mod sandbox;
|
||||||
pub mod secrets;
|
pub mod secrets;
|
||||||
pub mod settings;
|
pub mod settings;
|
||||||
pub mod setup;
|
pub mod setup;
|
||||||
pub mod tools;
|
pub mod tools;
|
||||||
|
pub mod tracing_fmt;
|
||||||
|
pub mod util;
|
||||||
|
pub mod worker;
|
||||||
pub mod workspace;
|
pub mod workspace;
|
||||||
|
|
||||||
pub use config::Config;
|
pub use config::Config;
|
||||||
|
|||||||
@@ -0,0 +1,124 @@
|
|||||||
|
//! Per-model cost lookup table for multi-provider LLM support.
|
||||||
|
//!
|
||||||
|
//! Returns (input_cost_per_token, output_cost_per_token) as Decimal pairs.
|
||||||
|
//! Ollama and other local models return zero cost.
|
||||||
|
|
||||||
|
use rust_decimal::Decimal;
|
||||||
|
use rust_decimal_macros::dec;
|
||||||
|
|
||||||
|
/// Look up known per-token costs for a model by its identifier.
|
||||||
|
///
|
||||||
|
/// Returns `Some((input_cost, output_cost))` for known models, `None` otherwise.
|
||||||
|
pub fn model_cost(model_id: &str) -> Option<(Decimal, Decimal)> {
|
||||||
|
// Normalize: strip provider prefixes (e.g., "openai/gpt-4o" -> "gpt-4o")
|
||||||
|
let id = model_id
|
||||||
|
.rsplit_once('/')
|
||||||
|
.map(|(_, name)| name)
|
||||||
|
.unwrap_or(model_id);
|
||||||
|
|
||||||
|
match id {
|
||||||
|
// OpenAI models -- prices per token (USD)
|
||||||
|
"gpt-4o" | "gpt-4o-2024-11-20" | "gpt-4o-2024-08-06" => {
|
||||||
|
Some((dec!(0.0000025), dec!(0.00001)))
|
||||||
|
}
|
||||||
|
"gpt-4o-mini" | "gpt-4o-mini-2024-07-18" => Some((dec!(0.00000015), dec!(0.0000006))),
|
||||||
|
"gpt-4-turbo" | "gpt-4-turbo-2024-04-09" => Some((dec!(0.00001), dec!(0.00003))),
|
||||||
|
"gpt-4" | "gpt-4-0613" => Some((dec!(0.00003), dec!(0.00006))),
|
||||||
|
"gpt-3.5-turbo" | "gpt-3.5-turbo-0125" => Some((dec!(0.0000005), dec!(0.0000015))),
|
||||||
|
"o1" | "o1-2024-12-17" => Some((dec!(0.000015), dec!(0.00006))),
|
||||||
|
"o1-mini" | "o1-mini-2024-09-12" => Some((dec!(0.000003), dec!(0.000012))),
|
||||||
|
"o3-mini" | "o3-mini-2025-01-31" => Some((dec!(0.0000011), dec!(0.0000044))),
|
||||||
|
|
||||||
|
// Anthropic models
|
||||||
|
"claude-3-5-sonnet-20241022" | "claude-3-5-sonnet-latest" | "claude-sonnet-4-20250514" => {
|
||||||
|
Some((dec!(0.000003), dec!(0.000015)))
|
||||||
|
}
|
||||||
|
"claude-3-5-haiku-20241022" | "claude-3-5-haiku-latest" => {
|
||||||
|
Some((dec!(0.0000008), dec!(0.000004)))
|
||||||
|
}
|
||||||
|
"claude-3-opus-20240229" | "claude-3-opus-latest" | "claude-opus-4-20250514" => {
|
||||||
|
Some((dec!(0.000015), dec!(0.000075)))
|
||||||
|
}
|
||||||
|
"claude-3-haiku-20240307" => Some((dec!(0.00000025), dec!(0.00000125))),
|
||||||
|
|
||||||
|
// Ollama / local models -- free
|
||||||
|
_ if is_local_model(id) => Some((Decimal::ZERO, Decimal::ZERO)),
|
||||||
|
|
||||||
|
_ => None,
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Default cost for unknown models.
|
||||||
|
pub fn default_cost() -> (Decimal, Decimal) {
|
||||||
|
// Conservative estimate: roughly GPT-4o pricing
|
||||||
|
(dec!(0.0000025), dec!(0.00001))
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Heuristic to detect local/self-hosted models (Ollama, llama.cpp, etc.).
|
||||||
|
fn is_local_model(model_id: &str) -> bool {
|
||||||
|
let lower = model_id.to_lowercase();
|
||||||
|
lower.starts_with("llama")
|
||||||
|
|| lower.starts_with("mistral")
|
||||||
|
|| lower.starts_with("mixtral")
|
||||||
|
|| lower.starts_with("phi")
|
||||||
|
|| lower.starts_with("gemma")
|
||||||
|
|| lower.starts_with("qwen")
|
||||||
|
|| lower.starts_with("codellama")
|
||||||
|
|| lower.starts_with("deepseek")
|
||||||
|
|| lower.starts_with("starcoder")
|
||||||
|
|| lower.starts_with("vicuna")
|
||||||
|
|| lower.starts_with("yi")
|
||||||
|
|| lower.contains(":latest")
|
||||||
|
|| lower.contains(":instruct")
|
||||||
|
}
|
||||||
|
|
||||||
|
#[cfg(test)]
|
||||||
|
mod tests {
|
||||||
|
use super::*;
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_known_model_costs() {
|
||||||
|
let (input, output) = model_cost("gpt-4o").unwrap();
|
||||||
|
assert!(input > Decimal::ZERO);
|
||||||
|
assert!(output > input);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_claude_costs() {
|
||||||
|
let (input, output) = model_cost("claude-3-5-sonnet-20241022").unwrap();
|
||||||
|
assert!(input > Decimal::ZERO);
|
||||||
|
assert!(output > input);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_local_model_free() {
|
||||||
|
let (input, output) = model_cost("llama3").unwrap();
|
||||||
|
assert_eq!(input, Decimal::ZERO);
|
||||||
|
assert_eq!(output, Decimal::ZERO);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_ollama_tagged_model_free() {
|
||||||
|
let (input, output) = model_cost("mistral:latest").unwrap();
|
||||||
|
assert_eq!(input, Decimal::ZERO);
|
||||||
|
assert_eq!(output, Decimal::ZERO);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_unknown_model_returns_none() {
|
||||||
|
assert!(model_cost("some-totally-unknown-model-xyz").is_none());
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_default_cost_nonzero() {
|
||||||
|
let (input, output) = default_cost();
|
||||||
|
assert!(input > Decimal::ZERO);
|
||||||
|
assert!(output > Decimal::ZERO);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_provider_prefix_stripped() {
|
||||||
|
// "openai/gpt-4o" should resolve to same as "gpt-4o"
|
||||||
|
assert_eq!(model_cost("openai/gpt-4o"), model_cost("gpt-4o"));
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,483 @@
|
|||||||
|
//! Multi-provider LLM failover.
|
||||||
|
//!
|
||||||
|
//! Wraps multiple LlmProvider instances and tries each in sequence
|
||||||
|
//! until one succeeds. Transparent to callers --- same LlmProvider trait.
|
||||||
|
|
||||||
|
use std::future::Future;
|
||||||
|
use std::sync::Arc;
|
||||||
|
use std::sync::atomic::{AtomicUsize, Ordering};
|
||||||
|
|
||||||
|
use async_trait::async_trait;
|
||||||
|
use rust_decimal::Decimal;
|
||||||
|
|
||||||
|
use crate::error::LlmError;
|
||||||
|
use crate::llm::provider::{
|
||||||
|
CompletionRequest, CompletionResponse, LlmProvider, ToolCompletionRequest,
|
||||||
|
ToolCompletionResponse,
|
||||||
|
};
|
||||||
|
|
||||||
|
/// Returns `true` if the error is transient and the request should be retried
|
||||||
|
/// on the next provider in the failover chain.
|
||||||
|
///
|
||||||
|
/// Retryable: `RequestFailed`, `RateLimited`, `InvalidResponse`,
|
||||||
|
/// `SessionRenewalFailed`, `ModelNotAvailable`, `Http`, `Io`.
|
||||||
|
///
|
||||||
|
/// `ModelNotAvailable` is retryable because the next provider in the chain may
|
||||||
|
/// offer a different model, so it's worth trying.
|
||||||
|
///
|
||||||
|
/// Non-retryable errors (`AuthFailed`, `SessionExpired`, `ContextLengthExceeded`)
|
||||||
|
/// propagate immediately because a different provider won't fix them.
|
||||||
|
fn is_retryable(err: &LlmError) -> bool {
|
||||||
|
matches!(
|
||||||
|
err,
|
||||||
|
LlmError::RequestFailed { .. }
|
||||||
|
| LlmError::RateLimited { .. }
|
||||||
|
| LlmError::InvalidResponse { .. }
|
||||||
|
| LlmError::SessionRenewalFailed { .. }
|
||||||
|
// ModelNotAvailable is retryable: the next provider may offer a different model.
|
||||||
|
| LlmError::ModelNotAvailable { .. }
|
||||||
|
| LlmError::Http(_)
|
||||||
|
| LlmError::Io(_)
|
||||||
|
)
|
||||||
|
}
|
||||||
|
|
||||||
|
/// An LLM provider that wraps multiple providers and tries each in sequence
|
||||||
|
/// on transient failures.
|
||||||
|
///
|
||||||
|
/// The first provider in the list is the primary. If it fails with a retryable
|
||||||
|
/// error, the next provider is tried, and so on. Non-retryable errors
|
||||||
|
/// (e.g. `AuthFailed`, `ContextLengthExceeded`) propagate immediately.
|
||||||
|
pub struct FailoverProvider {
|
||||||
|
providers: Vec<Arc<dyn LlmProvider>>,
|
||||||
|
/// Index of the provider that last handled a request successfully.
|
||||||
|
/// Used by `model_name()` and `cost_per_token()` so downstream cost
|
||||||
|
/// tracking reflects the provider that actually served the request.
|
||||||
|
last_used: AtomicUsize,
|
||||||
|
}
|
||||||
|
|
||||||
|
impl FailoverProvider {
|
||||||
|
/// Create a new failover provider.
|
||||||
|
///
|
||||||
|
/// Returns an error if `providers` is empty.
|
||||||
|
pub fn new(providers: Vec<Arc<dyn LlmProvider>>) -> Result<Self, LlmError> {
|
||||||
|
if providers.is_empty() {
|
||||||
|
return Err(LlmError::RequestFailed {
|
||||||
|
provider: "failover".to_string(),
|
||||||
|
reason: "FailoverProvider requires at least one provider".to_string(),
|
||||||
|
});
|
||||||
|
}
|
||||||
|
Ok(Self {
|
||||||
|
providers,
|
||||||
|
last_used: AtomicUsize::new(0),
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Try each provider in sequence until one succeeds or all fail.
|
||||||
|
async fn try_providers<T, F, Fut>(&self, mut call: F) -> Result<T, LlmError>
|
||||||
|
where
|
||||||
|
F: FnMut(Arc<dyn LlmProvider>) -> Fut,
|
||||||
|
Fut: Future<Output = Result<T, LlmError>>,
|
||||||
|
{
|
||||||
|
let mut last_error: Option<LlmError> = None;
|
||||||
|
|
||||||
|
for (i, provider) in self.providers.iter().enumerate() {
|
||||||
|
let result = call(Arc::clone(provider)).await;
|
||||||
|
match result {
|
||||||
|
Ok(response) => {
|
||||||
|
self.last_used.store(i, Ordering::Relaxed);
|
||||||
|
return Ok(response);
|
||||||
|
}
|
||||||
|
Err(err) => {
|
||||||
|
if !is_retryable(&err) {
|
||||||
|
return Err(err);
|
||||||
|
}
|
||||||
|
if i + 1 < self.providers.len() {
|
||||||
|
tracing::warn!(
|
||||||
|
provider = %provider.model_name(),
|
||||||
|
error = %err,
|
||||||
|
next_provider = %self.providers[i + 1].model_name(),
|
||||||
|
"Provider failed with retryable error, trying next provider"
|
||||||
|
);
|
||||||
|
}
|
||||||
|
last_error = Some(err);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// SAFETY: providers is non-empty (checked in `new`), so at least one
|
||||||
|
// iteration ran and `last_error` is `Some`.
|
||||||
|
Err(last_error.expect("providers list is non-empty"))
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
#[async_trait]
|
||||||
|
impl LlmProvider for FailoverProvider {
|
||||||
|
fn model_name(&self) -> &str {
|
||||||
|
self.providers[self.last_used.load(Ordering::Relaxed)].model_name()
|
||||||
|
}
|
||||||
|
|
||||||
|
fn cost_per_token(&self) -> (Decimal, Decimal) {
|
||||||
|
self.providers[self.last_used.load(Ordering::Relaxed)].cost_per_token()
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn complete(&self, request: CompletionRequest) -> Result<CompletionResponse, LlmError> {
|
||||||
|
self.try_providers(|provider| {
|
||||||
|
let req = request.clone();
|
||||||
|
async move { provider.complete(req).await }
|
||||||
|
})
|
||||||
|
.await
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn complete_with_tools(
|
||||||
|
&self,
|
||||||
|
request: ToolCompletionRequest,
|
||||||
|
) -> Result<ToolCompletionResponse, LlmError> {
|
||||||
|
self.try_providers(|provider| {
|
||||||
|
let req = request.clone();
|
||||||
|
async move { provider.complete_with_tools(req).await }
|
||||||
|
})
|
||||||
|
.await
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn list_models(&self) -> Result<Vec<String>, LlmError> {
|
||||||
|
let mut all_models = Vec::new();
|
||||||
|
|
||||||
|
for provider in &self.providers {
|
||||||
|
match provider.list_models().await {
|
||||||
|
Ok(models) => all_models.extend(models),
|
||||||
|
Err(err) => {
|
||||||
|
tracing::warn!(
|
||||||
|
provider = %provider.model_name(),
|
||||||
|
error = %err,
|
||||||
|
"Failed to list models from provider, skipping"
|
||||||
|
);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
all_models.sort();
|
||||||
|
all_models.dedup();
|
||||||
|
Ok(all_models)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
#[cfg(test)]
|
||||||
|
mod tests {
|
||||||
|
use super::*;
|
||||||
|
|
||||||
|
use std::sync::Mutex;
|
||||||
|
use std::time::Duration;
|
||||||
|
|
||||||
|
use crate::llm::provider::{CompletionResponse, FinishReason, ToolCompletionResponse};
|
||||||
|
|
||||||
|
/// A mock LLM provider that returns a predetermined result.
|
||||||
|
struct MockProvider {
|
||||||
|
name: String,
|
||||||
|
input_cost: Decimal,
|
||||||
|
output_cost: Decimal,
|
||||||
|
complete_result: Mutex<Option<Result<CompletionResponse, LlmError>>>,
|
||||||
|
tool_complete_result: Mutex<Option<Result<ToolCompletionResponse, LlmError>>>,
|
||||||
|
}
|
||||||
|
|
||||||
|
impl MockProvider {
|
||||||
|
fn succeeding(name: &str, content: &str) -> Self {
|
||||||
|
Self {
|
||||||
|
name: name.to_string(),
|
||||||
|
input_cost: Decimal::ZERO,
|
||||||
|
output_cost: Decimal::ZERO,
|
||||||
|
complete_result: Mutex::new(Some(Ok(CompletionResponse {
|
||||||
|
content: content.to_string(),
|
||||||
|
input_tokens: 10,
|
||||||
|
output_tokens: 5,
|
||||||
|
finish_reason: FinishReason::Stop,
|
||||||
|
response_id: None,
|
||||||
|
}))),
|
||||||
|
tool_complete_result: Mutex::new(Some(Ok(ToolCompletionResponse {
|
||||||
|
content: Some(content.to_string()),
|
||||||
|
tool_calls: vec![],
|
||||||
|
input_tokens: 10,
|
||||||
|
output_tokens: 5,
|
||||||
|
finish_reason: FinishReason::Stop,
|
||||||
|
response_id: None,
|
||||||
|
}))),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
fn succeeding_with_cost(
|
||||||
|
name: &str,
|
||||||
|
content: &str,
|
||||||
|
input_cost: Decimal,
|
||||||
|
output_cost: Decimal,
|
||||||
|
) -> Self {
|
||||||
|
Self {
|
||||||
|
input_cost,
|
||||||
|
output_cost,
|
||||||
|
..Self::succeeding(name, content)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
fn failing_retryable(name: &str) -> Self {
|
||||||
|
Self {
|
||||||
|
name: name.to_string(),
|
||||||
|
input_cost: Decimal::ZERO,
|
||||||
|
output_cost: Decimal::ZERO,
|
||||||
|
complete_result: Mutex::new(Some(Err(LlmError::RequestFailed {
|
||||||
|
provider: name.to_string(),
|
||||||
|
reason: "server error".to_string(),
|
||||||
|
}))),
|
||||||
|
tool_complete_result: Mutex::new(Some(Err(LlmError::RequestFailed {
|
||||||
|
provider: name.to_string(),
|
||||||
|
reason: "server error".to_string(),
|
||||||
|
}))),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
fn failing_non_retryable(name: &str) -> Self {
|
||||||
|
Self {
|
||||||
|
name: name.to_string(),
|
||||||
|
input_cost: Decimal::ZERO,
|
||||||
|
output_cost: Decimal::ZERO,
|
||||||
|
complete_result: Mutex::new(Some(Err(LlmError::AuthFailed {
|
||||||
|
provider: name.to_string(),
|
||||||
|
}))),
|
||||||
|
tool_complete_result: Mutex::new(Some(Err(LlmError::AuthFailed {
|
||||||
|
provider: name.to_string(),
|
||||||
|
}))),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
fn failing_rate_limited(name: &str) -> Self {
|
||||||
|
Self {
|
||||||
|
name: name.to_string(),
|
||||||
|
input_cost: Decimal::ZERO,
|
||||||
|
output_cost: Decimal::ZERO,
|
||||||
|
complete_result: Mutex::new(Some(Err(LlmError::RateLimited {
|
||||||
|
provider: name.to_string(),
|
||||||
|
retry_after: Some(Duration::from_secs(30)),
|
||||||
|
}))),
|
||||||
|
tool_complete_result: Mutex::new(Some(Err(LlmError::RateLimited {
|
||||||
|
provider: name.to_string(),
|
||||||
|
retry_after: Some(Duration::from_secs(30)),
|
||||||
|
}))),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
#[async_trait]
|
||||||
|
impl LlmProvider for MockProvider {
|
||||||
|
fn model_name(&self) -> &str {
|
||||||
|
&self.name
|
||||||
|
}
|
||||||
|
|
||||||
|
fn cost_per_token(&self) -> (Decimal, Decimal) {
|
||||||
|
(self.input_cost, self.output_cost)
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn complete(
|
||||||
|
&self,
|
||||||
|
_request: CompletionRequest,
|
||||||
|
) -> Result<CompletionResponse, LlmError> {
|
||||||
|
self.complete_result
|
||||||
|
.lock()
|
||||||
|
.unwrap()
|
||||||
|
.take()
|
||||||
|
.expect("MockProvider::complete called more than once")
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn complete_with_tools(
|
||||||
|
&self,
|
||||||
|
_request: ToolCompletionRequest,
|
||||||
|
) -> Result<ToolCompletionResponse, LlmError> {
|
||||||
|
self.tool_complete_result
|
||||||
|
.lock()
|
||||||
|
.unwrap()
|
||||||
|
.take()
|
||||||
|
.expect("MockProvider::complete_with_tools called more than once")
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn list_models(&self) -> Result<Vec<String>, LlmError> {
|
||||||
|
Ok(vec![self.name.clone()])
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
fn make_request() -> CompletionRequest {
|
||||||
|
CompletionRequest::new(vec![crate::llm::ChatMessage::user("hello")])
|
||||||
|
}
|
||||||
|
|
||||||
|
fn make_tool_request() -> ToolCompletionRequest {
|
||||||
|
ToolCompletionRequest::new(vec![crate::llm::ChatMessage::user("hello")], vec![])
|
||||||
|
}
|
||||||
|
|
||||||
|
// Test 1: Primary succeeds, no failover occurs.
|
||||||
|
#[tokio::test]
|
||||||
|
async fn primary_succeeds_no_failover() {
|
||||||
|
let primary = Arc::new(MockProvider::succeeding("primary", "primary response"));
|
||||||
|
let fallback = Arc::new(MockProvider::succeeding("fallback", "fallback response"));
|
||||||
|
|
||||||
|
let failover = FailoverProvider::new(vec![primary, fallback]).unwrap();
|
||||||
|
|
||||||
|
let response = failover.complete(make_request()).await.unwrap();
|
||||||
|
assert_eq!(response.content, "primary response");
|
||||||
|
}
|
||||||
|
|
||||||
|
// Test 2: Primary fails with retryable error, fallback succeeds.
|
||||||
|
#[tokio::test]
|
||||||
|
async fn primary_fails_retryable_fallback_succeeds() {
|
||||||
|
let primary = Arc::new(MockProvider::failing_retryable("primary"));
|
||||||
|
let fallback = Arc::new(MockProvider::succeeding("fallback", "fallback response"));
|
||||||
|
|
||||||
|
let failover = FailoverProvider::new(vec![primary, fallback]).unwrap();
|
||||||
|
|
||||||
|
let response = failover.complete(make_request()).await.unwrap();
|
||||||
|
assert_eq!(response.content, "fallback response");
|
||||||
|
}
|
||||||
|
|
||||||
|
// Test 3: All providers fail, returns last error.
|
||||||
|
#[tokio::test]
|
||||||
|
async fn all_providers_fail_returns_last_error() {
|
||||||
|
let primary = Arc::new(MockProvider::failing_retryable("primary"));
|
||||||
|
let fallback = Arc::new(MockProvider::failing_retryable("fallback"));
|
||||||
|
|
||||||
|
let failover = FailoverProvider::new(vec![primary, fallback]).unwrap();
|
||||||
|
|
||||||
|
let err = failover.complete(make_request()).await.unwrap_err();
|
||||||
|
match err {
|
||||||
|
LlmError::RequestFailed { provider, .. } => {
|
||||||
|
assert_eq!(provider, "fallback");
|
||||||
|
}
|
||||||
|
other => panic!("expected RequestFailed, got: {other:?}"),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// Test 4: Non-retryable error fails immediately, no failover.
|
||||||
|
#[tokio::test]
|
||||||
|
async fn non_retryable_error_fails_immediately() {
|
||||||
|
let primary = Arc::new(MockProvider::failing_non_retryable("primary"));
|
||||||
|
let fallback = Arc::new(MockProvider::succeeding("fallback", "fallback response"));
|
||||||
|
|
||||||
|
let failover = FailoverProvider::new(vec![primary, fallback]).unwrap();
|
||||||
|
|
||||||
|
let err = failover.complete(make_request()).await.unwrap_err();
|
||||||
|
match err {
|
||||||
|
LlmError::AuthFailed { provider } => {
|
||||||
|
assert_eq!(provider, "primary");
|
||||||
|
}
|
||||||
|
other => panic!("expected AuthFailed, got: {other:?}"),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// Test 5: Three providers, first two fail (retryable), third succeeds.
|
||||||
|
#[tokio::test]
|
||||||
|
async fn three_providers_first_two_fail_third_succeeds() {
|
||||||
|
let p1 = Arc::new(MockProvider::failing_retryable("provider-1"));
|
||||||
|
let p2 = Arc::new(MockProvider::failing_rate_limited("provider-2"));
|
||||||
|
let p3 = Arc::new(MockProvider::succeeding("provider-3", "third time lucky"));
|
||||||
|
|
||||||
|
let failover = FailoverProvider::new(vec![p1, p2, p3]).unwrap();
|
||||||
|
|
||||||
|
let response = failover.complete(make_request()).await.unwrap();
|
||||||
|
assert_eq!(response.content, "third time lucky");
|
||||||
|
}
|
||||||
|
|
||||||
|
// Test: complete_with_tools follows same failover logic.
|
||||||
|
#[tokio::test]
|
||||||
|
async fn complete_with_tools_failover() {
|
||||||
|
let primary = Arc::new(MockProvider::failing_retryable("primary"));
|
||||||
|
let fallback = Arc::new(MockProvider::succeeding("fallback", "tools fallback"));
|
||||||
|
|
||||||
|
let failover = FailoverProvider::new(vec![primary, fallback]).unwrap();
|
||||||
|
|
||||||
|
let response = failover
|
||||||
|
.complete_with_tools(make_tool_request())
|
||||||
|
.await
|
||||||
|
.unwrap();
|
||||||
|
assert_eq!(response.content.as_deref(), Some("tools fallback"));
|
||||||
|
}
|
||||||
|
|
||||||
|
// Test: model_name and cost_per_token reflect the last-used provider.
|
||||||
|
#[tokio::test]
|
||||||
|
async fn model_name_and_cost_track_last_used_provider() {
|
||||||
|
let fallback_cost = Decimal::new(15, 6); // 0.000015
|
||||||
|
|
||||||
|
let primary = Arc::new(MockProvider::failing_retryable("primary-model"));
|
||||||
|
let fallback = Arc::new(MockProvider::succeeding_with_cost(
|
||||||
|
"fallback-model",
|
||||||
|
"ok",
|
||||||
|
fallback_cost,
|
||||||
|
fallback_cost,
|
||||||
|
));
|
||||||
|
|
||||||
|
let failover = FailoverProvider::new(vec![primary, fallback]).unwrap();
|
||||||
|
|
||||||
|
// Before any call, defaults to primary (index 0).
|
||||||
|
assert_eq!(failover.model_name(), "primary-model");
|
||||||
|
assert_eq!(failover.cost_per_token(), (Decimal::ZERO, Decimal::ZERO));
|
||||||
|
|
||||||
|
// After failover, should reflect the fallback provider.
|
||||||
|
let _ = failover.complete(make_request()).await.unwrap();
|
||||||
|
assert_eq!(failover.model_name(), "fallback-model");
|
||||||
|
assert_eq!(failover.cost_per_token(), (fallback_cost, fallback_cost));
|
||||||
|
}
|
||||||
|
|
||||||
|
// Test: list_models aggregates from all providers.
|
||||||
|
#[tokio::test]
|
||||||
|
async fn list_models_aggregates_all() {
|
||||||
|
let p1 = Arc::new(MockProvider::succeeding("model-a", "ok"));
|
||||||
|
let p2 = Arc::new(MockProvider::succeeding("model-b", "ok"));
|
||||||
|
|
||||||
|
let failover = FailoverProvider::new(vec![p1, p2]).unwrap();
|
||||||
|
|
||||||
|
let models = failover.list_models().await.unwrap();
|
||||||
|
assert!(models.contains(&"model-a".to_string()));
|
||||||
|
assert!(models.contains(&"model-b".to_string()));
|
||||||
|
}
|
||||||
|
|
||||||
|
// Test: is_retryable correctly classifies errors.
|
||||||
|
#[test]
|
||||||
|
fn retryable_classification() {
|
||||||
|
// Retryable
|
||||||
|
assert!(is_retryable(&LlmError::RequestFailed {
|
||||||
|
provider: "p".into(),
|
||||||
|
reason: "err".into(),
|
||||||
|
}));
|
||||||
|
assert!(is_retryable(&LlmError::RateLimited {
|
||||||
|
provider: "p".into(),
|
||||||
|
retry_after: None,
|
||||||
|
}));
|
||||||
|
assert!(is_retryable(&LlmError::InvalidResponse {
|
||||||
|
provider: "p".into(),
|
||||||
|
reason: "bad json".into(),
|
||||||
|
}));
|
||||||
|
assert!(is_retryable(&LlmError::SessionRenewalFailed {
|
||||||
|
provider: "p".into(),
|
||||||
|
reason: "timeout".into(),
|
||||||
|
}));
|
||||||
|
assert!(is_retryable(&LlmError::Io(std::io::Error::new(
|
||||||
|
std::io::ErrorKind::ConnectionReset,
|
||||||
|
"reset"
|
||||||
|
))));
|
||||||
|
assert!(is_retryable(&LlmError::ModelNotAvailable {
|
||||||
|
provider: "p".into(),
|
||||||
|
model: "m".into(),
|
||||||
|
}));
|
||||||
|
|
||||||
|
// Non-retryable
|
||||||
|
assert!(!is_retryable(&LlmError::AuthFailed {
|
||||||
|
provider: "p".into(),
|
||||||
|
}));
|
||||||
|
assert!(!is_retryable(&LlmError::SessionExpired {
|
||||||
|
provider: "p".into(),
|
||||||
|
}));
|
||||||
|
assert!(!is_retryable(&LlmError::ContextLengthExceeded {
|
||||||
|
used: 100_000,
|
||||||
|
limit: 50_000,
|
||||||
|
}));
|
||||||
|
}
|
||||||
|
|
||||||
|
// Test: empty providers list returns error (not panic).
|
||||||
|
#[test]
|
||||||
|
fn empty_providers_returns_error() {
|
||||||
|
let result = FailoverProvider::new(vec![]);
|
||||||
|
assert!(result.is_err());
|
||||||
|
}
|
||||||
|
}
|
||||||
+257
-17
@@ -1,48 +1,288 @@
|
|||||||
//! LLM integration for the agent.
|
//! LLM integration for the agent.
|
||||||
//!
|
//!
|
||||||
//! Supports two API modes:
|
//! Supports multiple backends:
|
||||||
//! - **Responses API** (chat-api): Session-based auth, uses `/v1/responses` endpoint
|
//! - **NEAR AI** (default): Session-based or API key auth via NEAR AI proxy
|
||||||
//! - **Chat Completions API** (cloud-api): API key auth, uses `/v1/chat/completions` endpoint
|
//! - **OpenAI**: Direct API access with your own key
|
||||||
|
//! - **Anthropic**: Direct API access with your own key
|
||||||
|
//! - **Ollama**: Local model inference
|
||||||
|
//! - **OpenAI-compatible**: Any endpoint that speaks the OpenAI API
|
||||||
|
|
||||||
|
mod costs;
|
||||||
|
pub mod failover;
|
||||||
mod nearai;
|
mod nearai;
|
||||||
mod nearai_chat;
|
mod nearai_chat;
|
||||||
mod provider;
|
mod provider;
|
||||||
mod reasoning;
|
mod reasoning;
|
||||||
|
mod retry;
|
||||||
|
mod rig_adapter;
|
||||||
pub mod session;
|
pub mod session;
|
||||||
|
|
||||||
|
pub use failover::FailoverProvider;
|
||||||
pub use nearai::{ModelInfo, NearAiProvider};
|
pub use nearai::{ModelInfo, NearAiProvider};
|
||||||
pub use nearai_chat::NearAiChatProvider;
|
pub use nearai_chat::NearAiChatProvider;
|
||||||
pub use provider::{
|
pub use provider::{
|
||||||
ChatMessage, CompletionRequest, CompletionResponse, LlmProvider, Role, ToolCall,
|
ChatMessage, CompletionRequest, CompletionResponse, FinishReason, LlmProvider, ModelMetadata,
|
||||||
ToolCompletionRequest, ToolCompletionResponse, ToolDefinition, ToolResult,
|
Role, ToolCall, ToolCompletionRequest, ToolCompletionResponse, ToolDefinition, ToolResult,
|
||||||
};
|
};
|
||||||
pub use reasoning::{ActionPlan, Reasoning, ReasoningContext, RespondResult, ToolSelection};
|
pub use reasoning::{
|
||||||
|
ActionPlan, Reasoning, ReasoningContext, RespondOutput, RespondResult, TokenUsage,
|
||||||
|
ToolSelection,
|
||||||
|
};
|
||||||
|
pub use rig_adapter::RigAdapter;
|
||||||
pub use session::{SessionConfig, SessionManager, create_session_manager};
|
pub use session::{SessionConfig, SessionManager, create_session_manager};
|
||||||
|
|
||||||
use std::sync::Arc;
|
use std::sync::Arc;
|
||||||
|
|
||||||
use crate::config::{LlmConfig, NearAiApiMode};
|
use rig::client::CompletionClient;
|
||||||
|
use secrecy::ExposeSecret;
|
||||||
|
|
||||||
|
use crate::config::{LlmBackend, LlmConfig, NearAiApiMode, NearAiConfig};
|
||||||
use crate::error::LlmError;
|
use crate::error::LlmError;
|
||||||
|
|
||||||
/// Create an LLM provider based on configuration.
|
/// Create an LLM provider based on configuration.
|
||||||
///
|
///
|
||||||
/// - For `Responses` mode: Requires a session manager for authentication
|
/// - `NearAi` backend: Uses session manager for authentication (Responses API)
|
||||||
/// - For `ChatCompletions` mode: Uses API key from config (session not needed)
|
/// or API key (Chat Completions API)
|
||||||
|
/// - Other backends: Use rig-core adapter with provider-specific clients
|
||||||
pub fn create_llm_provider(
|
pub fn create_llm_provider(
|
||||||
config: &LlmConfig,
|
config: &LlmConfig,
|
||||||
session: Arc<SessionManager>,
|
session: Arc<SessionManager>,
|
||||||
) -> Result<Arc<dyn LlmProvider>, LlmError> {
|
) -> Result<Arc<dyn LlmProvider>, LlmError> {
|
||||||
match config.nearai.api_mode {
|
match config.backend {
|
||||||
|
LlmBackend::NearAi => create_llm_provider_with_config(&config.nearai, session),
|
||||||
|
LlmBackend::OpenAi => create_openai_provider(config),
|
||||||
|
LlmBackend::Anthropic => create_anthropic_provider(config),
|
||||||
|
LlmBackend::Ollama => create_ollama_provider(config),
|
||||||
|
LlmBackend::OpenAiCompatible => create_openai_compatible_provider(config),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Create an LLM provider from a `NearAiConfig` directly.
|
||||||
|
///
|
||||||
|
/// This is useful when constructing additional providers for failover,
|
||||||
|
/// where only the model name differs from the primary config.
|
||||||
|
pub fn create_llm_provider_with_config(
|
||||||
|
config: &NearAiConfig,
|
||||||
|
session: Arc<SessionManager>,
|
||||||
|
) -> Result<Arc<dyn LlmProvider>, LlmError> {
|
||||||
|
match config.api_mode {
|
||||||
NearAiApiMode::Responses => {
|
NearAiApiMode::Responses => {
|
||||||
tracing::info!("Using Responses API (chat-api) with session auth");
|
tracing::info!(
|
||||||
Ok(Arc::new(NearAiProvider::new(
|
model = %config.model,
|
||||||
config.nearai.clone(),
|
"Using Responses API (chat-api) with session auth"
|
||||||
session,
|
);
|
||||||
)))
|
Ok(Arc::new(NearAiProvider::new(config.clone(), session)))
|
||||||
}
|
}
|
||||||
NearAiApiMode::ChatCompletions => {
|
NearAiApiMode::ChatCompletions => {
|
||||||
tracing::info!("Using Chat Completions API (cloud-api) with API key auth");
|
tracing::info!(
|
||||||
Ok(Arc::new(NearAiChatProvider::new(config.nearai.clone())?))
|
model = %config.model,
|
||||||
|
"Using Chat Completions API (cloud-api) with API key auth"
|
||||||
|
);
|
||||||
|
Ok(Arc::new(NearAiChatProvider::new(config.clone())?))
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
fn create_openai_provider(config: &LlmConfig) -> Result<Arc<dyn LlmProvider>, LlmError> {
|
||||||
|
let oai = config.openai.as_ref().ok_or_else(|| LlmError::AuthFailed {
|
||||||
|
provider: "openai".to_string(),
|
||||||
|
})?;
|
||||||
|
|
||||||
|
use rig::providers::openai;
|
||||||
|
|
||||||
|
let client: openai::Client =
|
||||||
|
openai::Client::new(oai.api_key.expose_secret()).map_err(|e| LlmError::RequestFailed {
|
||||||
|
provider: "openai".to_string(),
|
||||||
|
reason: format!("Failed to create OpenAI client: {}", e),
|
||||||
|
})?;
|
||||||
|
|
||||||
|
let model = client.completion_model(&oai.model);
|
||||||
|
tracing::info!("Using OpenAI direct API (model: {})", oai.model);
|
||||||
|
Ok(Arc::new(RigAdapter::new(model, &oai.model)))
|
||||||
|
}
|
||||||
|
|
||||||
|
fn create_anthropic_provider(config: &LlmConfig) -> Result<Arc<dyn LlmProvider>, LlmError> {
|
||||||
|
let anth = config
|
||||||
|
.anthropic
|
||||||
|
.as_ref()
|
||||||
|
.ok_or_else(|| LlmError::AuthFailed {
|
||||||
|
provider: "anthropic".to_string(),
|
||||||
|
})?;
|
||||||
|
|
||||||
|
use rig::providers::anthropic;
|
||||||
|
|
||||||
|
let client: anthropic::Client =
|
||||||
|
anthropic::Client::new(anth.api_key.expose_secret()).map_err(|e| {
|
||||||
|
LlmError::RequestFailed {
|
||||||
|
provider: "anthropic".to_string(),
|
||||||
|
reason: format!("Failed to create Anthropic client: {}", e),
|
||||||
|
}
|
||||||
|
})?;
|
||||||
|
|
||||||
|
let model = client.completion_model(&anth.model);
|
||||||
|
tracing::info!("Using Anthropic direct API (model: {})", anth.model);
|
||||||
|
Ok(Arc::new(RigAdapter::new(model, &anth.model)))
|
||||||
|
}
|
||||||
|
|
||||||
|
fn create_ollama_provider(config: &LlmConfig) -> Result<Arc<dyn LlmProvider>, LlmError> {
|
||||||
|
let oll = config.ollama.as_ref().ok_or_else(|| LlmError::AuthFailed {
|
||||||
|
provider: "ollama".to_string(),
|
||||||
|
})?;
|
||||||
|
|
||||||
|
use rig::client::Nothing;
|
||||||
|
use rig::providers::ollama;
|
||||||
|
|
||||||
|
let client: ollama::Client = ollama::Client::builder()
|
||||||
|
.base_url(&oll.base_url)
|
||||||
|
.api_key(Nothing)
|
||||||
|
.build()
|
||||||
|
.map_err(|e| LlmError::RequestFailed {
|
||||||
|
provider: "ollama".to_string(),
|
||||||
|
reason: format!("Failed to create Ollama client: {}", e),
|
||||||
|
})?;
|
||||||
|
|
||||||
|
let model = client.completion_model(&oll.model);
|
||||||
|
tracing::info!(
|
||||||
|
"Using Ollama (base_url: {}, model: {})",
|
||||||
|
oll.base_url,
|
||||||
|
oll.model
|
||||||
|
);
|
||||||
|
Ok(Arc::new(RigAdapter::new(model, &oll.model)))
|
||||||
|
}
|
||||||
|
|
||||||
|
fn create_openai_compatible_provider(config: &LlmConfig) -> Result<Arc<dyn LlmProvider>, LlmError> {
|
||||||
|
let compat = config
|
||||||
|
.openai_compatible
|
||||||
|
.as_ref()
|
||||||
|
.ok_or_else(|| LlmError::AuthFailed {
|
||||||
|
provider: "openai_compatible".to_string(),
|
||||||
|
})?;
|
||||||
|
|
||||||
|
use rig::providers::openai;
|
||||||
|
|
||||||
|
let api_key = compat
|
||||||
|
.api_key
|
||||||
|
.as_ref()
|
||||||
|
.map(|k| k.expose_secret().to_string())
|
||||||
|
.unwrap_or_else(|| "no-key".to_string());
|
||||||
|
|
||||||
|
let client: openai::Client = openai::Client::builder()
|
||||||
|
.base_url(&compat.base_url)
|
||||||
|
.api_key(api_key)
|
||||||
|
.build()
|
||||||
|
.map_err(|e| LlmError::RequestFailed {
|
||||||
|
provider: "openai_compatible".to_string(),
|
||||||
|
reason: format!("Failed to create OpenAI-compatible client: {}", e),
|
||||||
|
})?;
|
||||||
|
|
||||||
|
let model = client.completion_model(&compat.model);
|
||||||
|
tracing::info!(
|
||||||
|
"Using OpenAI-compatible endpoint (base_url: {}, model: {})",
|
||||||
|
compat.base_url,
|
||||||
|
compat.model
|
||||||
|
);
|
||||||
|
Ok(Arc::new(RigAdapter::new(model, &compat.model)))
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Create a cheap/fast LLM provider for lightweight tasks (heartbeat, routing, evaluation).
|
||||||
|
///
|
||||||
|
/// Uses `NEARAI_CHEAP_MODEL` if set, otherwise falls back to the main provider.
|
||||||
|
/// Currently only supports NEAR AI backends (Responses and ChatCompletions modes).
|
||||||
|
pub fn create_cheap_llm_provider(
|
||||||
|
config: &LlmConfig,
|
||||||
|
session: Arc<SessionManager>,
|
||||||
|
) -> Result<Option<Arc<dyn LlmProvider>>, LlmError> {
|
||||||
|
let Some(ref cheap_model) = config.nearai.cheap_model else {
|
||||||
|
return Ok(None);
|
||||||
|
};
|
||||||
|
|
||||||
|
if config.backend != LlmBackend::NearAi {
|
||||||
|
tracing::warn!(
|
||||||
|
"NEARAI_CHEAP_MODEL is set but LLM_BACKEND is {:?}, not NearAi. \
|
||||||
|
Cheap model setting will be ignored.",
|
||||||
|
config.backend
|
||||||
|
);
|
||||||
|
return Ok(None);
|
||||||
|
}
|
||||||
|
|
||||||
|
let mut cheap_config = config.nearai.clone();
|
||||||
|
cheap_config.model = cheap_model.clone();
|
||||||
|
|
||||||
|
tracing::info!("Cheap LLM provider: {}", cheap_model);
|
||||||
|
|
||||||
|
match cheap_config.api_mode {
|
||||||
|
NearAiApiMode::Responses => Ok(Some(Arc::new(NearAiProvider::new(cheap_config, session)))),
|
||||||
|
NearAiApiMode::ChatCompletions => {
|
||||||
|
Ok(Some(Arc::new(NearAiChatProvider::new(cheap_config)?)))
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
#[cfg(test)]
|
||||||
|
mod tests {
|
||||||
|
use super::*;
|
||||||
|
use crate::config::{LlmBackend, NearAiApiMode, NearAiConfig};
|
||||||
|
use std::path::PathBuf;
|
||||||
|
|
||||||
|
fn test_nearai_config() -> NearAiConfig {
|
||||||
|
NearAiConfig {
|
||||||
|
model: "test-model".to_string(),
|
||||||
|
cheap_model: None,
|
||||||
|
base_url: "https://api.near.ai".to_string(),
|
||||||
|
auth_base_url: "https://private.near.ai".to_string(),
|
||||||
|
session_path: PathBuf::from("/tmp/test-session.json"),
|
||||||
|
api_mode: NearAiApiMode::Responses,
|
||||||
|
api_key: None,
|
||||||
|
fallback_model: None,
|
||||||
|
max_retries: 3,
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
fn test_llm_config() -> LlmConfig {
|
||||||
|
LlmConfig {
|
||||||
|
backend: LlmBackend::NearAi,
|
||||||
|
nearai: test_nearai_config(),
|
||||||
|
openai: None,
|
||||||
|
anthropic: None,
|
||||||
|
ollama: None,
|
||||||
|
openai_compatible: None,
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_create_cheap_llm_provider_returns_none_when_not_configured() {
|
||||||
|
let config = test_llm_config();
|
||||||
|
let session = Arc::new(SessionManager::new(SessionConfig::default()));
|
||||||
|
|
||||||
|
let result = create_cheap_llm_provider(&config, session);
|
||||||
|
assert!(result.is_ok());
|
||||||
|
assert!(result.unwrap().is_none());
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_create_cheap_llm_provider_creates_provider_when_configured() {
|
||||||
|
let mut config = test_llm_config();
|
||||||
|
config.nearai.cheap_model = Some("cheap-test-model".to_string());
|
||||||
|
|
||||||
|
let session = Arc::new(SessionManager::new(SessionConfig::default()));
|
||||||
|
let result = create_cheap_llm_provider(&config, session);
|
||||||
|
|
||||||
|
assert!(result.is_ok());
|
||||||
|
let provider = result.unwrap();
|
||||||
|
assert!(provider.is_some());
|
||||||
|
assert_eq!(provider.unwrap().model_name(), "cheap-test-model");
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_create_cheap_llm_provider_ignored_for_non_nearai_backend() {
|
||||||
|
let mut config = test_llm_config();
|
||||||
|
config.backend = LlmBackend::OpenAi;
|
||||||
|
config.nearai.cheap_model = Some("cheap-test-model".to_string());
|
||||||
|
|
||||||
|
let session = Arc::new(SessionManager::new(SessionConfig::default()));
|
||||||
|
let result = create_cheap_llm_provider(&config, session);
|
||||||
|
|
||||||
|
assert!(result.is_ok());
|
||||||
|
assert!(result.unwrap().is_none());
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|||||||
+382
-52
@@ -3,6 +3,7 @@
|
|||||||
//! This provider uses the NEAR AI chat-api which provides a unified interface
|
//! This provider uses the NEAR AI chat-api which provides a unified interface
|
||||||
//! to multiple LLM models (OpenAI, Anthropic, etc.) with user authentication.
|
//! to multiple LLM models (OpenAI, Anthropic, etc.) with user authentication.
|
||||||
|
|
||||||
|
use std::collections::HashMap;
|
||||||
use std::sync::Arc;
|
use std::sync::Arc;
|
||||||
|
|
||||||
use async_trait::async_trait;
|
use async_trait::async_trait;
|
||||||
@@ -18,6 +19,7 @@ use crate::llm::provider::{
|
|||||||
ChatMessage, CompletionRequest, CompletionResponse, FinishReason, LlmProvider, Role, ToolCall,
|
ChatMessage, CompletionRequest, CompletionResponse, FinishReason, LlmProvider, Role, ToolCall,
|
||||||
ToolCompletionRequest, ToolCompletionResponse,
|
ToolCompletionRequest, ToolCompletionResponse,
|
||||||
};
|
};
|
||||||
|
use crate::llm::retry::{is_retryable_status, retry_backoff_delay};
|
||||||
use crate::llm::session::SessionManager;
|
use crate::llm::session::SessionManager;
|
||||||
|
|
||||||
/// Information about an available model from NEAR AI API.
|
/// Information about an available model from NEAR AI API.
|
||||||
@@ -31,11 +33,23 @@ pub struct ModelInfo {
|
|||||||
pub provider: Option<String>,
|
pub provider: Option<String>,
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/// Per-thread chaining state: the last response ID and how many input
|
||||||
|
/// messages were included in that request. This lets subsequent calls send
|
||||||
|
/// only the delta (new messages since last call).
|
||||||
|
struct ChainState {
|
||||||
|
response_id: String,
|
||||||
|
input_count: usize,
|
||||||
|
}
|
||||||
|
|
||||||
/// NEAR AI Chat API provider.
|
/// NEAR AI Chat API provider.
|
||||||
pub struct NearAiProvider {
|
pub struct NearAiProvider {
|
||||||
client: Client,
|
client: Client,
|
||||||
config: NearAiConfig,
|
config: NearAiConfig,
|
||||||
session: Arc<SessionManager>,
|
session: Arc<SessionManager>,
|
||||||
|
active_model: std::sync::RwLock<String>,
|
||||||
|
/// Per-thread response ID chaining state.
|
||||||
|
/// Key is thread_id from request metadata.
|
||||||
|
response_chains: std::sync::RwLock<HashMap<String, ChainState>>,
|
||||||
}
|
}
|
||||||
|
|
||||||
impl NearAiProvider {
|
impl NearAiProvider {
|
||||||
@@ -46,13 +60,64 @@ impl NearAiProvider {
|
|||||||
.build()
|
.build()
|
||||||
.unwrap_or_else(|_| Client::new());
|
.unwrap_or_else(|_| Client::new());
|
||||||
|
|
||||||
|
let active_model = std::sync::RwLock::new(config.model.clone());
|
||||||
Self {
|
Self {
|
||||||
client,
|
client,
|
||||||
config,
|
config,
|
||||||
session,
|
session,
|
||||||
|
active_model,
|
||||||
|
response_chains: std::sync::RwLock::new(HashMap::new()),
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/// Seed a response chain for a thread (e.g. when restoring from DB).
|
||||||
|
pub fn seed_response_id(&self, thread_id: &str, response_id: String) {
|
||||||
|
let mut chains = self
|
||||||
|
.response_chains
|
||||||
|
.write()
|
||||||
|
.expect("response_chains lock poisoned");
|
||||||
|
chains.insert(
|
||||||
|
thread_id.to_string(),
|
||||||
|
ChainState {
|
||||||
|
response_id,
|
||||||
|
input_count: 0,
|
||||||
|
},
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Get the last response ID for a thread (for persistence).
|
||||||
|
pub fn get_response_id(&self, thread_id: &str) -> Option<String> {
|
||||||
|
let chains = self
|
||||||
|
.response_chains
|
||||||
|
.read()
|
||||||
|
.expect("response_chains lock poisoned");
|
||||||
|
chains.get(thread_id).map(|c| c.response_id.clone())
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Store a response chain state after a successful call.
|
||||||
|
fn store_chain(&self, thread_id: &str, response_id: String, input_count: usize) {
|
||||||
|
let mut chains = self
|
||||||
|
.response_chains
|
||||||
|
.write()
|
||||||
|
.expect("response_chains lock poisoned");
|
||||||
|
chains.insert(
|
||||||
|
thread_id.to_string(),
|
||||||
|
ChainState {
|
||||||
|
response_id,
|
||||||
|
input_count,
|
||||||
|
},
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Clear the chain for a thread (on error / fallback).
|
||||||
|
fn clear_chain(&self, thread_id: &str) {
|
||||||
|
let mut chains = self
|
||||||
|
.response_chains
|
||||||
|
.write()
|
||||||
|
.expect("response_chains lock poisoned");
|
||||||
|
chains.remove(thread_id);
|
||||||
|
}
|
||||||
|
|
||||||
fn api_url(&self, path: &str) -> String {
|
fn api_url(&self, path: &str) -> String {
|
||||||
format!(
|
format!(
|
||||||
"{}/v1/{}",
|
"{}/v1/{}",
|
||||||
@@ -145,8 +210,9 @@ impl NearAiProvider {
|
|||||||
data: Option<Vec<ModelEntry>>,
|
data: Option<Vec<ModelEntry>>,
|
||||||
}
|
}
|
||||||
|
|
||||||
if let Ok(resp) = serde_json::from_str::<ModelsResponse>(&response_text) {
|
if let Ok(resp) = serde_json::from_str::<ModelsResponse>(&response_text)
|
||||||
if let Some(entries) = resp.models.or(resp.data) {
|
&& let Some(entries) = resp.models.or(resp.data)
|
||||||
|
{
|
||||||
let models: Vec<ModelInfo> = entries
|
let models: Vec<ModelInfo> = entries
|
||||||
.into_iter()
|
.into_iter()
|
||||||
.filter_map(|e| {
|
.filter_map(|e| {
|
||||||
@@ -160,7 +226,6 @@ impl NearAiProvider {
|
|||||||
return Ok(models);
|
return Ok(models);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
|
||||||
|
|
||||||
// Try direct array format
|
// Try direct array format
|
||||||
if let Ok(entries) = serde_json::from_str::<Vec<ModelEntry>>(&response_text) {
|
if let Ok(entries) = serde_json::from_str::<Vec<ModelEntry>>(&response_text) {
|
||||||
@@ -206,16 +271,26 @@ impl NearAiProvider {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
/// Inner request implementation without retry logic.
|
/// Inner request implementation with retry logic for transient errors.
|
||||||
|
///
|
||||||
|
/// Retries on HTTP 429, 500, 502, 503, 504 with exponential backoff.
|
||||||
|
/// Does not retry on client errors (400, 401, 403, 404) or parse errors.
|
||||||
async fn send_request_inner<T: Serialize + std::fmt::Debug, R: for<'de> Deserialize<'de>>(
|
async fn send_request_inner<T: Serialize + std::fmt::Debug, R: for<'de> Deserialize<'de>>(
|
||||||
&self,
|
&self,
|
||||||
path: &str,
|
path: &str,
|
||||||
body: &T,
|
body: &T,
|
||||||
) -> Result<R, LlmError> {
|
) -> Result<R, LlmError> {
|
||||||
let url = self.api_url(path);
|
let url = self.api_url(path);
|
||||||
|
let max_retries = self.config.max_retries;
|
||||||
|
|
||||||
|
for attempt in 0..=max_retries {
|
||||||
let token = self.session.get_token().await?;
|
let token = self.session.get_token().await?;
|
||||||
|
|
||||||
tracing::debug!("Sending request to NEAR AI: {}", url);
|
tracing::debug!(
|
||||||
|
"Sending request to NEAR AI: {} (attempt {})",
|
||||||
|
url,
|
||||||
|
attempt + 1
|
||||||
|
);
|
||||||
tracing::debug!("Request body: {:?}", body);
|
tracing::debug!("Request body: {:?}", body);
|
||||||
|
|
||||||
let response = self
|
let response = self
|
||||||
@@ -225,11 +300,28 @@ impl NearAiProvider {
|
|||||||
.header("Content-Type", "application/json")
|
.header("Content-Type", "application/json")
|
||||||
.json(body)
|
.json(body)
|
||||||
.send()
|
.send()
|
||||||
.await
|
.await;
|
||||||
.map_err(|e| {
|
|
||||||
|
let response = match response {
|
||||||
|
Ok(r) => r,
|
||||||
|
Err(e) => {
|
||||||
tracing::error!("NEAR AI request failed: {}", e);
|
tracing::error!("NEAR AI request failed: {}", e);
|
||||||
e
|
// Network errors (timeout, connection refused) are transient
|
||||||
})?;
|
if attempt < max_retries {
|
||||||
|
let delay = retry_backoff_delay(attempt);
|
||||||
|
tracing::warn!(
|
||||||
|
"NEAR AI request error (attempt {}/{}), retrying in {:?}: {}",
|
||||||
|
attempt + 1,
|
||||||
|
max_retries + 1,
|
||||||
|
delay,
|
||||||
|
e,
|
||||||
|
);
|
||||||
|
tokio::time::sleep(delay).await;
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
return Err(e.into());
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
let status = response.status();
|
let status = response.status();
|
||||||
let response_text = response.text().await.unwrap_or_default();
|
let response_text = response.text().await.unwrap_or_default();
|
||||||
@@ -238,11 +330,13 @@ impl NearAiProvider {
|
|||||||
tracing::debug!("NEAR AI response body: {}", response_text);
|
tracing::debug!("NEAR AI response body: {}", response_text);
|
||||||
|
|
||||||
if !status.is_success() {
|
if !status.is_success() {
|
||||||
|
let status_code = status.as_u16();
|
||||||
|
|
||||||
// Check for session expiration (401 with specific message patterns)
|
// Check for session expiration (401 with specific message patterns)
|
||||||
if status.as_u16() == 401 {
|
if status_code == 401 {
|
||||||
let is_session_expired = response_text.to_lowercase().contains("session")
|
let lower = response_text.to_lowercase();
|
||||||
&& (response_text.to_lowercase().contains("expired")
|
let is_session_expired = lower.contains("session")
|
||||||
|| response_text.to_lowercase().contains("invalid"));
|
&& (lower.contains("expired") || lower.contains("invalid"));
|
||||||
|
|
||||||
if is_session_expired {
|
if is_session_expired {
|
||||||
return Err(LlmError::SessionExpired {
|
return Err(LlmError::SessionExpired {
|
||||||
@@ -250,15 +344,29 @@ impl NearAiProvider {
|
|||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
// Generic 401 without session expiration indication
|
// Generic 401 -- not retryable
|
||||||
return Err(LlmError::AuthFailed {
|
return Err(LlmError::AuthFailed {
|
||||||
provider: "nearai".to_string(),
|
provider: "nearai".to_string(),
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
// Try to parse as JSON error
|
// Check if this is a transient error worth retrying
|
||||||
|
if is_retryable_status(status_code) && attempt < max_retries {
|
||||||
|
let delay = retry_backoff_delay(attempt);
|
||||||
|
tracing::warn!(
|
||||||
|
"NEAR AI returned HTTP {} (attempt {}/{}), retrying in {:?}",
|
||||||
|
status_code,
|
||||||
|
attempt + 1,
|
||||||
|
max_retries + 1,
|
||||||
|
delay,
|
||||||
|
);
|
||||||
|
tokio::time::sleep(delay).await;
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
|
||||||
|
// Non-retryable error or exhausted retries
|
||||||
if let Ok(error) = serde_json::from_str::<NearAiErrorResponse>(&response_text) {
|
if let Ok(error) = serde_json::from_str::<NearAiErrorResponse>(&response_text) {
|
||||||
if status.as_u16() == 429 {
|
if status_code == 429 {
|
||||||
return Err(LlmError::RateLimited {
|
return Err(LlmError::RateLimited {
|
||||||
provider: "nearai".to_string(),
|
provider: "nearai".to_string(),
|
||||||
retry_after: None,
|
retry_after: None,
|
||||||
@@ -276,8 +384,8 @@ impl NearAiProvider {
|
|||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
// Try to parse as our expected type
|
// Success -- parse the response
|
||||||
match serde_json::from_str::<R>(&response_text) {
|
return match serde_json::from_str::<R>(&response_text) {
|
||||||
Ok(parsed) => Ok(parsed),
|
Ok(parsed) => Ok(parsed),
|
||||||
Err(e) => {
|
Err(e) => {
|
||||||
tracing::debug!("Response is not expected JSON format: {}", e);
|
tracing::debug!("Response is not expected JSON format: {}", e);
|
||||||
@@ -287,22 +395,46 @@ impl NearAiProvider {
|
|||||||
reason: format!("Parse error: {}. Raw: {}", e, response_text),
|
reason: format!("Parse error: {}. Raw: {}", e, response_text),
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
|
};
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// This is unreachable because the loop always returns, but the compiler
|
||||||
|
// cannot prove that. Return a generic error as a safety net.
|
||||||
|
Err(LlmError::RequestFailed {
|
||||||
|
provider: "nearai".to_string(),
|
||||||
|
reason: "retry loop exited unexpectedly".to_string(),
|
||||||
|
})
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
/// Split messages into system instructions and non-system input messages.
|
/// Split messages into system instructions and non-system input items.
|
||||||
/// The OpenAI Responses API expects system prompts in an `instructions` field,
|
/// The OpenAI Responses API expects system prompts in an `instructions` field,
|
||||||
/// not as a message with role "system" in the input array.
|
/// not as a message with role "system" in the input array.
|
||||||
fn split_messages(messages: Vec<ChatMessage>) -> (Option<String>, Vec<NearAiMessage>) {
|
///
|
||||||
|
/// When `chaining` is true, tool result messages (role=tool) are converted to
|
||||||
|
/// `NearAiInputItem::FunctionCallOutput` for the Responses API protocol.
|
||||||
|
fn split_messages(
|
||||||
|
messages: Vec<ChatMessage>,
|
||||||
|
chaining: bool,
|
||||||
|
) -> (Option<String>, Vec<NearAiInputItem>) {
|
||||||
let mut instructions: Vec<String> = Vec::new();
|
let mut instructions: Vec<String> = Vec::new();
|
||||||
let mut input: Vec<NearAiMessage> = Vec::new();
|
let mut input: Vec<NearAiInputItem> = Vec::new();
|
||||||
|
|
||||||
for msg in messages {
|
for msg in messages {
|
||||||
if msg.role == Role::System {
|
if msg.role == Role::System {
|
||||||
instructions.push(msg.content);
|
instructions.push(msg.content);
|
||||||
|
} else if chaining && msg.role == Role::Tool {
|
||||||
|
if let Some(ref call_id) = msg.tool_call_id {
|
||||||
|
input.push(NearAiInputItem::FunctionCallOutput {
|
||||||
|
item_type: "function_call_output".to_string(),
|
||||||
|
call_id: call_id.clone(),
|
||||||
|
output: msg.content,
|
||||||
|
});
|
||||||
} else {
|
} else {
|
||||||
input.push(msg.into());
|
input.push(NearAiInputItem::Message(msg.into()));
|
||||||
|
}
|
||||||
|
} else {
|
||||||
|
input.push(NearAiInputItem::Message(msg.into()));
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -318,12 +450,14 @@ fn split_messages(messages: Vec<ChatMessage>) -> (Option<String>, Vec<NearAiMess
|
|||||||
#[async_trait]
|
#[async_trait]
|
||||||
impl LlmProvider for NearAiProvider {
|
impl LlmProvider for NearAiProvider {
|
||||||
async fn complete(&self, req: CompletionRequest) -> Result<CompletionResponse, LlmError> {
|
async fn complete(&self, req: CompletionRequest) -> Result<CompletionResponse, LlmError> {
|
||||||
let (instructions, input) = split_messages(req.messages);
|
let thread_id = req.metadata.get("thread_id").cloned();
|
||||||
|
let (instructions, input) = split_messages(req.messages, false);
|
||||||
|
|
||||||
let request = NearAiRequest {
|
let request = NearAiRequest {
|
||||||
model: self.config.model.clone(),
|
model: self.active_model_name(),
|
||||||
instructions,
|
instructions,
|
||||||
input,
|
input,
|
||||||
|
previous_response_id: None,
|
||||||
temperature: req.temperature,
|
temperature: req.temperature,
|
||||||
max_output_tokens: req.max_tokens,
|
max_output_tokens: req.max_tokens,
|
||||||
stream: Some(false),
|
stream: Some(false),
|
||||||
@@ -350,6 +484,7 @@ impl LlmProvider for NearAiProvider {
|
|||||||
finish_reason: FinishReason::Stop,
|
finish_reason: FinishReason::Stop,
|
||||||
input_tokens: usage.input_tokens,
|
input_tokens: usage.input_tokens,
|
||||||
output_tokens: usage.output_tokens,
|
output_tokens: usage.output_tokens,
|
||||||
|
response_id: None,
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -367,12 +502,13 @@ impl LlmProvider for NearAiProvider {
|
|||||||
finish_reason: FinishReason::Stop,
|
finish_reason: FinishReason::Stop,
|
||||||
input_tokens: 0,
|
input_tokens: 0,
|
||||||
output_tokens: 0,
|
output_tokens: 0,
|
||||||
|
response_id: None,
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
Err(e) => return Err(e),
|
Err(e) => return Err(e),
|
||||||
};
|
};
|
||||||
|
|
||||||
tracing::debug!("NEAR AI response: {:?}", response);
|
tracing::debug!("NEAR AI response: output_items={}", response.output.len());
|
||||||
|
|
||||||
// Extract text from response output
|
// Extract text from response output
|
||||||
// Try multiple formats since API response shape may vary
|
// Try multiple formats since API response shape may vary
|
||||||
@@ -380,11 +516,6 @@ impl LlmProvider for NearAiProvider {
|
|||||||
.output
|
.output
|
||||||
.iter()
|
.iter()
|
||||||
.filter_map(|item| {
|
.filter_map(|item| {
|
||||||
tracing::debug!(
|
|
||||||
"Processing output item: type={}, text={:?}",
|
|
||||||
item.item_type,
|
|
||||||
item.text
|
|
||||||
);
|
|
||||||
if item.item_type == "message" {
|
if item.item_type == "message" {
|
||||||
// First check for direct text field on item
|
// First check for direct text field on item
|
||||||
if let Some(ref text) = item.text {
|
if let Some(ref text) = item.text {
|
||||||
@@ -395,11 +526,6 @@ impl LlmProvider for NearAiProvider {
|
|||||||
contents
|
contents
|
||||||
.iter()
|
.iter()
|
||||||
.filter_map(|c| {
|
.filter_map(|c| {
|
||||||
tracing::debug!(
|
|
||||||
"Content item: type={}, text={:?}",
|
|
||||||
c.content_type,
|
|
||||||
c.text
|
|
||||||
);
|
|
||||||
// Accept various content types that might contain text
|
// Accept various content types that might contain text
|
||||||
match c.content_type.as_str() {
|
match c.content_type.as_str() {
|
||||||
"output_text" | "text" => c.text.clone(),
|
"output_text" | "text" => c.text.clone(),
|
||||||
@@ -423,11 +549,17 @@ impl LlmProvider for NearAiProvider {
|
|||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Store response ID for chaining
|
||||||
|
if let Some(ref tid) = thread_id {
|
||||||
|
self.store_chain(tid, response.id.clone(), 0);
|
||||||
|
}
|
||||||
|
|
||||||
Ok(CompletionResponse {
|
Ok(CompletionResponse {
|
||||||
content: text,
|
content: text,
|
||||||
finish_reason: FinishReason::Stop,
|
finish_reason: FinishReason::Stop,
|
||||||
input_tokens: response.usage.input_tokens,
|
input_tokens: response.usage.input_tokens,
|
||||||
output_tokens: response.usage.output_tokens,
|
output_tokens: response.usage.output_tokens,
|
||||||
|
response_id: Some(response.id),
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -435,7 +567,33 @@ impl LlmProvider for NearAiProvider {
|
|||||||
&self,
|
&self,
|
||||||
req: ToolCompletionRequest,
|
req: ToolCompletionRequest,
|
||||||
) -> Result<ToolCompletionResponse, LlmError> {
|
) -> Result<ToolCompletionResponse, LlmError> {
|
||||||
let (instructions, input) = split_messages(req.messages);
|
let thread_id = req.metadata.get("thread_id").cloned();
|
||||||
|
|
||||||
|
// Look up chaining state for this thread
|
||||||
|
let chain_state = thread_id.as_ref().and_then(|tid| {
|
||||||
|
let chains = self
|
||||||
|
.response_chains
|
||||||
|
.read()
|
||||||
|
.expect("response_chains lock poisoned");
|
||||||
|
chains
|
||||||
|
.get(tid)
|
||||||
|
.map(|c| (c.response_id.clone(), c.input_count))
|
||||||
|
});
|
||||||
|
|
||||||
|
let chaining = chain_state.is_some();
|
||||||
|
let (previous_response_id, prev_input_count) = chain_state
|
||||||
|
.map(|(rid, count)| (Some(rid), count))
|
||||||
|
.unwrap_or((None, 0));
|
||||||
|
|
||||||
|
// When chaining, only send new messages (the delta since last call).
|
||||||
|
// Tool results are converted to function_call_output items.
|
||||||
|
let (instructions, all_input) = split_messages(req.messages, chaining);
|
||||||
|
let input = if chaining && all_input.len() > prev_input_count {
|
||||||
|
all_input[prev_input_count..].to_vec()
|
||||||
|
} else {
|
||||||
|
all_input.clone()
|
||||||
|
};
|
||||||
|
let total_input_count = all_input.len();
|
||||||
|
|
||||||
let tools: Vec<NearAiTool> = req
|
let tools: Vec<NearAiTool> = req
|
||||||
.tools
|
.tools
|
||||||
@@ -449,18 +607,58 @@ impl LlmProvider for NearAiProvider {
|
|||||||
.collect();
|
.collect();
|
||||||
|
|
||||||
let request = NearAiRequest {
|
let request = NearAiRequest {
|
||||||
model: self.config.model.clone(),
|
model: self.active_model_name(),
|
||||||
instructions,
|
instructions: if chaining { None } else { instructions.clone() },
|
||||||
input,
|
input,
|
||||||
|
previous_response_id: previous_response_id.clone(),
|
||||||
temperature: req.temperature,
|
temperature: req.temperature,
|
||||||
max_output_tokens: req.max_tokens,
|
max_output_tokens: req.max_tokens,
|
||||||
stream: Some(false),
|
stream: Some(false),
|
||||||
tools: if tools.is_empty() { None } else { Some(tools) },
|
tools: if tools.is_empty() {
|
||||||
|
None
|
||||||
|
} else {
|
||||||
|
Some(tools.clone())
|
||||||
|
},
|
||||||
};
|
};
|
||||||
|
|
||||||
// Try to get structured response, fall back to alternative formats
|
// Try to get structured response, fall back to alternative formats.
|
||||||
|
// If chaining fails (bad previous_response_id), retry with full history.
|
||||||
let response: NearAiResponse = match self.send_request("responses", &request).await {
|
let response: NearAiResponse = match self.send_request("responses", &request).await {
|
||||||
Ok(r) => r,
|
Ok(r) => r,
|
||||||
|
Err(ref e) if chaining && is_chain_error(e) => {
|
||||||
|
tracing::warn!(
|
||||||
|
"Response chaining failed, retrying with full history: {}",
|
||||||
|
e
|
||||||
|
);
|
||||||
|
if let Some(ref tid) = thread_id {
|
||||||
|
self.clear_chain(tid);
|
||||||
|
}
|
||||||
|
let (instructions_full, input_full) = split_messages(
|
||||||
|
// Rebuild from the original input (non-chaining mode)
|
||||||
|
{
|
||||||
|
let mut msgs = Vec::new();
|
||||||
|
if let Some(ref instr) = instructions {
|
||||||
|
msgs.push(ChatMessage::system(instr.clone()));
|
||||||
|
}
|
||||||
|
for item in &all_input {
|
||||||
|
msgs.push(item.to_chat_message());
|
||||||
|
}
|
||||||
|
msgs
|
||||||
|
},
|
||||||
|
false,
|
||||||
|
);
|
||||||
|
let retry_request = NearAiRequest {
|
||||||
|
model: self.active_model_name(),
|
||||||
|
instructions: instructions_full,
|
||||||
|
input: input_full,
|
||||||
|
previous_response_id: None,
|
||||||
|
temperature: request.temperature,
|
||||||
|
max_output_tokens: request.max_output_tokens,
|
||||||
|
stream: Some(false),
|
||||||
|
tools: request.tools.clone(),
|
||||||
|
};
|
||||||
|
self.send_request("responses", &retry_request).await?
|
||||||
|
}
|
||||||
Err(LlmError::InvalidResponse { reason, .. }) if reason.contains("Raw: ") => {
|
Err(LlmError::InvalidResponse { reason, .. }) if reason.contains("Raw: ") => {
|
||||||
let raw_text = reason.split("Raw: ").nth(1).unwrap_or("");
|
let raw_text = reason.split("Raw: ").nth(1).unwrap_or("");
|
||||||
|
|
||||||
@@ -490,6 +688,7 @@ impl LlmProvider for NearAiProvider {
|
|||||||
finish_reason,
|
finish_reason,
|
||||||
input_tokens: usage.input_tokens,
|
input_tokens: usage.input_tokens,
|
||||||
output_tokens: usage.output_tokens,
|
output_tokens: usage.output_tokens,
|
||||||
|
response_id: None,
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -507,6 +706,7 @@ impl LlmProvider for NearAiProvider {
|
|||||||
finish_reason: FinishReason::Stop,
|
finish_reason: FinishReason::Stop,
|
||||||
input_tokens: 0,
|
input_tokens: 0,
|
||||||
output_tokens: 0,
|
output_tokens: 0,
|
||||||
|
response_id: None,
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
Err(e) => return Err(e),
|
Err(e) => return Err(e),
|
||||||
@@ -536,8 +736,9 @@ impl LlmProvider for NearAiProvider {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
} else if item.item_type == "function_call" {
|
} else if item.item_type == "function_call"
|
||||||
if let (Some(name), Some(call_id)) = (&item.name, &item.call_id) {
|
&& let (Some(name), Some(call_id)) = (&item.name, &item.call_id)
|
||||||
|
{
|
||||||
// Parse arguments JSON string into Value
|
// Parse arguments JSON string into Value
|
||||||
let arguments = item
|
let arguments = item
|
||||||
.arguments
|
.arguments
|
||||||
@@ -552,7 +753,6 @@ impl LlmProvider for NearAiProvider {
|
|||||||
});
|
});
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
|
||||||
|
|
||||||
let finish_reason = if tool_calls.is_empty() {
|
let finish_reason = if tool_calls.is_empty() {
|
||||||
FinishReason::Stop
|
FinishReason::Stop
|
||||||
@@ -560,12 +760,18 @@ impl LlmProvider for NearAiProvider {
|
|||||||
FinishReason::ToolUse
|
FinishReason::ToolUse
|
||||||
};
|
};
|
||||||
|
|
||||||
|
// Store response ID for chaining on subsequent calls
|
||||||
|
if let Some(ref tid) = thread_id {
|
||||||
|
self.store_chain(tid, response.id.clone(), total_input_count);
|
||||||
|
}
|
||||||
|
|
||||||
Ok(ToolCompletionResponse {
|
Ok(ToolCompletionResponse {
|
||||||
content: if text.is_empty() { None } else { Some(text) },
|
content: if text.is_empty() { None } else { Some(text) },
|
||||||
tool_calls,
|
tool_calls,
|
||||||
finish_reason,
|
finish_reason,
|
||||||
input_tokens: response.usage.input_tokens,
|
input_tokens: response.usage.input_tokens,
|
||||||
output_tokens: response.usage.output_tokens,
|
output_tokens: response.usage.output_tokens,
|
||||||
|
response_id: Some(response.id),
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -584,6 +790,30 @@ impl LlmProvider for NearAiProvider {
|
|||||||
let models = NearAiProvider::list_models(self).await?;
|
let models = NearAiProvider::list_models(self).await?;
|
||||||
Ok(models.into_iter().map(|m| m.name).collect())
|
Ok(models.into_iter().map(|m| m.name).collect())
|
||||||
}
|
}
|
||||||
|
|
||||||
|
fn active_model_name(&self) -> String {
|
||||||
|
self.active_model
|
||||||
|
.read()
|
||||||
|
.expect("active_model lock poisoned")
|
||||||
|
.clone()
|
||||||
|
}
|
||||||
|
|
||||||
|
fn set_model(&self, model: &str) -> Result<(), LlmError> {
|
||||||
|
let mut guard = self
|
||||||
|
.active_model
|
||||||
|
.write()
|
||||||
|
.expect("active_model lock poisoned");
|
||||||
|
*guard = model.to_string();
|
||||||
|
Ok(())
|
||||||
|
}
|
||||||
|
|
||||||
|
fn seed_response_chain(&self, thread_id: &str, response_id: String) {
|
||||||
|
self.seed_response_id(thread_id, response_id);
|
||||||
|
}
|
||||||
|
|
||||||
|
fn get_response_chain_id(&self, thread_id: &str) -> Option<String> {
|
||||||
|
self.get_response_id(thread_id)
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// NEAR AI API types
|
// NEAR AI API types
|
||||||
@@ -597,8 +827,11 @@ struct NearAiRequest {
|
|||||||
/// System instructions (replaces sending system role in input)
|
/// System instructions (replaces sending system role in input)
|
||||||
#[serde(skip_serializing_if = "Option::is_none")]
|
#[serde(skip_serializing_if = "Option::is_none")]
|
||||||
instructions: Option<String>,
|
instructions: Option<String>,
|
||||||
/// Input messages (user/assistant/tool only, NOT system)
|
/// Input items: messages and/or function_call_output entries.
|
||||||
input: Vec<NearAiMessage>,
|
input: Vec<NearAiInputItem>,
|
||||||
|
/// Chain this request to a previous response (avoids resending full context).
|
||||||
|
#[serde(skip_serializing_if = "Option::is_none")]
|
||||||
|
previous_response_id: Option<String>,
|
||||||
#[serde(skip_serializing_if = "Option::is_none")]
|
#[serde(skip_serializing_if = "Option::is_none")]
|
||||||
temperature: Option<f32>,
|
temperature: Option<f32>,
|
||||||
#[serde(skip_serializing_if = "Option::is_none")]
|
#[serde(skip_serializing_if = "Option::is_none")]
|
||||||
@@ -609,7 +842,7 @@ struct NearAiRequest {
|
|||||||
tools: Option<Vec<NearAiTool>>,
|
tools: Option<Vec<NearAiTool>>,
|
||||||
}
|
}
|
||||||
|
|
||||||
#[derive(Debug, Serialize, Deserialize)]
|
#[derive(Debug, Serialize, Deserialize, Clone)]
|
||||||
struct NearAiMessage {
|
struct NearAiMessage {
|
||||||
role: String,
|
role: String,
|
||||||
content: String,
|
content: String,
|
||||||
@@ -630,7 +863,68 @@ impl From<ChatMessage> for NearAiMessage {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
#[derive(Debug, Serialize)]
|
/// Input item for the Responses API. Either a regular message or a
|
||||||
|
/// function_call_output (for returning tool results when chaining).
|
||||||
|
#[derive(Debug, Serialize, Deserialize, Clone)]
|
||||||
|
#[serde(untagged)]
|
||||||
|
enum NearAiInputItem {
|
||||||
|
Message(NearAiMessage),
|
||||||
|
FunctionCallOutput {
|
||||||
|
#[serde(rename = "type")]
|
||||||
|
item_type: String,
|
||||||
|
call_id: String,
|
||||||
|
output: String,
|
||||||
|
},
|
||||||
|
}
|
||||||
|
|
||||||
|
impl NearAiInputItem {
|
||||||
|
/// Convert back to a ChatMessage (used for fallback retry).
|
||||||
|
fn to_chat_message(&self) -> ChatMessage {
|
||||||
|
match self {
|
||||||
|
NearAiInputItem::Message(msg) => {
|
||||||
|
let role = match msg.role.as_str() {
|
||||||
|
"system" => Role::System,
|
||||||
|
"user" => Role::User,
|
||||||
|
"assistant" => Role::Assistant,
|
||||||
|
"tool" => Role::Tool,
|
||||||
|
_ => Role::User,
|
||||||
|
};
|
||||||
|
ChatMessage {
|
||||||
|
role,
|
||||||
|
content: msg.content.clone(),
|
||||||
|
tool_call_id: None,
|
||||||
|
name: None,
|
||||||
|
tool_calls: None,
|
||||||
|
}
|
||||||
|
}
|
||||||
|
NearAiInputItem::FunctionCallOutput {
|
||||||
|
call_id, output, ..
|
||||||
|
} => ChatMessage {
|
||||||
|
role: Role::Tool,
|
||||||
|
content: output.clone(),
|
||||||
|
tool_call_id: Some(call_id.clone()),
|
||||||
|
name: None,
|
||||||
|
tool_calls: None,
|
||||||
|
},
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Check if an LLM error is likely caused by an invalid previous_response_id.
|
||||||
|
fn is_chain_error(err: &LlmError) -> bool {
|
||||||
|
match err {
|
||||||
|
LlmError::RequestFailed { reason, .. } => {
|
||||||
|
let lower = reason.to_lowercase();
|
||||||
|
lower.contains("previous_response_id")
|
||||||
|
|| lower.contains("previous response")
|
||||||
|
|| lower.contains("not found")
|
||||||
|
|| lower.contains("invalid response id")
|
||||||
|
}
|
||||||
|
_ => false,
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
#[derive(Debug, Clone, Serialize)]
|
||||||
struct NearAiTool {
|
struct NearAiTool {
|
||||||
#[serde(rename = "type")]
|
#[serde(rename = "type")]
|
||||||
tool_type: String,
|
tool_type: String,
|
||||||
@@ -833,14 +1127,17 @@ mod tests {
|
|||||||
ChatMessage::user("Hello"),
|
ChatMessage::user("Hello"),
|
||||||
ChatMessage::assistant("Hi there!"),
|
ChatMessage::assistant("Hi there!"),
|
||||||
];
|
];
|
||||||
let (instructions, input) = split_messages(messages);
|
let (instructions, input) = split_messages(messages, false);
|
||||||
assert_eq!(
|
assert_eq!(
|
||||||
instructions,
|
instructions,
|
||||||
Some("You are a helpful assistant".to_string())
|
Some("You are a helpful assistant".to_string())
|
||||||
);
|
);
|
||||||
assert_eq!(input.len(), 2);
|
assert_eq!(input.len(), 2);
|
||||||
assert_eq!(input[0].role, "user");
|
// Verify the input items are messages
|
||||||
assert_eq!(input[1].role, "assistant");
|
match &input[0] {
|
||||||
|
NearAiInputItem::Message(m) => assert_eq!(m.role, "user"),
|
||||||
|
_ => panic!("expected Message"),
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
#[test]
|
#[test]
|
||||||
@@ -849,7 +1146,7 @@ mod tests {
|
|||||||
ChatMessage::user("Hello"),
|
ChatMessage::user("Hello"),
|
||||||
ChatMessage::assistant("Hi there!"),
|
ChatMessage::assistant("Hi there!"),
|
||||||
];
|
];
|
||||||
let (instructions, input) = split_messages(messages);
|
let (instructions, input) = split_messages(messages, false);
|
||||||
assert!(instructions.is_none());
|
assert!(instructions.is_none());
|
||||||
assert_eq!(input.len(), 2);
|
assert_eq!(input.len(), 2);
|
||||||
}
|
}
|
||||||
@@ -861,11 +1158,44 @@ mod tests {
|
|||||||
ChatMessage::system("Second instruction"),
|
ChatMessage::system("Second instruction"),
|
||||||
ChatMessage::user("Hello"),
|
ChatMessage::user("Hello"),
|
||||||
];
|
];
|
||||||
let (instructions, input) = split_messages(messages);
|
let (instructions, input) = split_messages(messages, false);
|
||||||
assert_eq!(
|
assert_eq!(
|
||||||
instructions,
|
instructions,
|
||||||
Some("First instruction\n\nSecond instruction".to_string())
|
Some("First instruction\n\nSecond instruction".to_string())
|
||||||
);
|
);
|
||||||
assert_eq!(input.len(), 1);
|
assert_eq!(input.len(), 1);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_split_messages_chaining_converts_tool_results() {
|
||||||
|
let messages = vec![
|
||||||
|
ChatMessage::user("Hello"),
|
||||||
|
ChatMessage::tool_result("call_123", "my_tool", "result data"),
|
||||||
|
];
|
||||||
|
let (_, input) = split_messages(messages, true);
|
||||||
|
assert_eq!(input.len(), 2);
|
||||||
|
match &input[1] {
|
||||||
|
NearAiInputItem::FunctionCallOutput {
|
||||||
|
call_id, output, ..
|
||||||
|
} => {
|
||||||
|
assert_eq!(call_id, "call_123");
|
||||||
|
assert_eq!(output, "result data");
|
||||||
|
}
|
||||||
|
_ => panic!("expected FunctionCallOutput"),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_split_messages_no_chaining_keeps_tool_as_message() {
|
||||||
|
let messages = vec![
|
||||||
|
ChatMessage::user("Hello"),
|
||||||
|
ChatMessage::tool_result("call_123", "my_tool", "result data"),
|
||||||
|
];
|
||||||
|
let (_, input) = split_messages(messages, false);
|
||||||
|
assert_eq!(input.len(), 2);
|
||||||
|
match &input[1] {
|
||||||
|
NearAiInputItem::Message(m) => assert_eq!(m.role, "tool"),
|
||||||
|
_ => panic!("expected Message"),
|
||||||
|
}
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
+311
-27
@@ -13,14 +13,16 @@ use serde::{Deserialize, Serialize};
|
|||||||
use crate::config::NearAiConfig;
|
use crate::config::NearAiConfig;
|
||||||
use crate::error::LlmError;
|
use crate::error::LlmError;
|
||||||
use crate::llm::provider::{
|
use crate::llm::provider::{
|
||||||
ChatMessage, CompletionRequest, CompletionResponse, FinishReason, LlmProvider, Role, ToolCall,
|
ChatMessage, CompletionRequest, CompletionResponse, FinishReason, LlmProvider, ModelMetadata,
|
||||||
ToolCompletionRequest, ToolCompletionResponse,
|
Role, ToolCall, ToolCompletionRequest, ToolCompletionResponse,
|
||||||
};
|
};
|
||||||
|
use crate::llm::retry::{is_retryable_status, retry_backoff_delay};
|
||||||
|
|
||||||
/// NEAR AI Chat Completions API provider.
|
/// NEAR AI Chat Completions API provider.
|
||||||
pub struct NearAiChatProvider {
|
pub struct NearAiChatProvider {
|
||||||
client: Client,
|
client: Client,
|
||||||
config: NearAiConfig,
|
config: NearAiConfig,
|
||||||
|
active_model: std::sync::RwLock<String>,
|
||||||
}
|
}
|
||||||
|
|
||||||
impl NearAiChatProvider {
|
impl NearAiChatProvider {
|
||||||
@@ -37,7 +39,12 @@ impl NearAiChatProvider {
|
|||||||
.build()
|
.build()
|
||||||
.unwrap_or_else(|_| Client::new());
|
.unwrap_or_else(|_| Client::new());
|
||||||
|
|
||||||
Ok(Self { client, config })
|
let active_model = std::sync::RwLock::new(config.model.clone());
|
||||||
|
Ok(Self {
|
||||||
|
client,
|
||||||
|
config,
|
||||||
|
active_model,
|
||||||
|
})
|
||||||
}
|
}
|
||||||
|
|
||||||
fn api_url(&self, path: &str) -> String {
|
fn api_url(&self, path: &str) -> String {
|
||||||
@@ -56,14 +63,29 @@ impl NearAiChatProvider {
|
|||||||
.unwrap_or_default()
|
.unwrap_or_default()
|
||||||
}
|
}
|
||||||
|
|
||||||
/// Send a request to the chat completions API.
|
/// Send a request to the chat completions API with retry on transient errors.
|
||||||
|
///
|
||||||
|
/// Retries on HTTP 429, 500, 502, 503, 504 with exponential backoff.
|
||||||
|
/// Does not retry on client errors (400, 401, 403, 404) or parse errors.
|
||||||
async fn send_request<T: Serialize, R: for<'de> Deserialize<'de>>(
|
async fn send_request<T: Serialize, R: for<'de> Deserialize<'de>>(
|
||||||
&self,
|
&self,
|
||||||
body: &T,
|
body: &T,
|
||||||
) -> Result<R, LlmError> {
|
) -> Result<R, LlmError> {
|
||||||
let url = self.api_url("chat/completions");
|
let url = self.api_url("chat/completions");
|
||||||
|
let max_retries = self.config.max_retries;
|
||||||
|
|
||||||
tracing::debug!("Sending request to NEAR AI Chat: {}", url);
|
for attempt in 0..=max_retries {
|
||||||
|
tracing::debug!(
|
||||||
|
"Sending request to NEAR AI Chat: {} (attempt {})",
|
||||||
|
url,
|
||||||
|
attempt + 1,
|
||||||
|
);
|
||||||
|
|
||||||
|
if tracing::enabled!(tracing::Level::DEBUG)
|
||||||
|
&& let Ok(json) = serde_json::to_string(body)
|
||||||
|
{
|
||||||
|
tracing::debug!("NEAR AI Chat request body: {}", json);
|
||||||
|
}
|
||||||
|
|
||||||
let response = self
|
let response = self
|
||||||
.client
|
.client
|
||||||
@@ -72,14 +94,30 @@ impl NearAiChatProvider {
|
|||||||
.header("Content-Type", "application/json")
|
.header("Content-Type", "application/json")
|
||||||
.json(body)
|
.json(body)
|
||||||
.send()
|
.send()
|
||||||
.await
|
.await;
|
||||||
.map_err(|e| {
|
|
||||||
|
let response = match response {
|
||||||
|
Ok(r) => r,
|
||||||
|
Err(e) => {
|
||||||
tracing::error!("NEAR AI Chat request failed: {}", e);
|
tracing::error!("NEAR AI Chat request failed: {}", e);
|
||||||
LlmError::RequestFailed {
|
if attempt < max_retries {
|
||||||
|
let delay = retry_backoff_delay(attempt);
|
||||||
|
tracing::warn!(
|
||||||
|
"NEAR AI Chat request error (attempt {}/{}), retrying in {:?}: {}",
|
||||||
|
attempt + 1,
|
||||||
|
max_retries + 1,
|
||||||
|
delay,
|
||||||
|
e,
|
||||||
|
);
|
||||||
|
tokio::time::sleep(delay).await;
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
return Err(LlmError::RequestFailed {
|
||||||
provider: "nearai_chat".to_string(),
|
provider: "nearai_chat".to_string(),
|
||||||
reason: e.to_string(),
|
reason: e.to_string(),
|
||||||
|
});
|
||||||
}
|
}
|
||||||
})?;
|
};
|
||||||
|
|
||||||
let status = response.status();
|
let status = response.status();
|
||||||
let response_text = response.text().await.unwrap_or_default();
|
let response_text = response.text().await.unwrap_or_default();
|
||||||
@@ -88,12 +126,31 @@ impl NearAiChatProvider {
|
|||||||
tracing::debug!("NEAR AI Chat response body: {}", response_text);
|
tracing::debug!("NEAR AI Chat response body: {}", response_text);
|
||||||
|
|
||||||
if !status.is_success() {
|
if !status.is_success() {
|
||||||
if status.as_u16() == 401 {
|
let status_code = status.as_u16();
|
||||||
|
|
||||||
|
// Auth errors are not retryable
|
||||||
|
if status_code == 401 {
|
||||||
return Err(LlmError::AuthFailed {
|
return Err(LlmError::AuthFailed {
|
||||||
provider: "nearai_chat".to_string(),
|
provider: "nearai_chat".to_string(),
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
if status.as_u16() == 429 {
|
|
||||||
|
// Transient errors: retry with backoff
|
||||||
|
if is_retryable_status(status_code) && attempt < max_retries {
|
||||||
|
let delay = retry_backoff_delay(attempt);
|
||||||
|
tracing::warn!(
|
||||||
|
"NEAR AI Chat returned HTTP {} (attempt {}/{}), retrying in {:?}",
|
||||||
|
status_code,
|
||||||
|
attempt + 1,
|
||||||
|
max_retries + 1,
|
||||||
|
delay,
|
||||||
|
);
|
||||||
|
tokio::time::sleep(delay).await;
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
|
||||||
|
// Non-retryable or exhausted retries
|
||||||
|
if status_code == 429 {
|
||||||
return Err(LlmError::RateLimited {
|
return Err(LlmError::RateLimited {
|
||||||
provider: "nearai_chat".to_string(),
|
provider: "nearai_chat".to_string(),
|
||||||
retry_after: None,
|
retry_after: None,
|
||||||
@@ -105,14 +162,22 @@ impl NearAiChatProvider {
|
|||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
serde_json::from_str(&response_text).map_err(|e| LlmError::InvalidResponse {
|
// Success — parse the response
|
||||||
|
return serde_json::from_str(&response_text).map_err(|e| LlmError::InvalidResponse {
|
||||||
provider: "nearai_chat".to_string(),
|
provider: "nearai_chat".to_string(),
|
||||||
reason: format!("JSON parse error: {}. Raw: {}", e, response_text),
|
reason: format!("JSON parse error: {}. Raw: {}", e, response_text),
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
// Safety net: unreachable because the loop always returns
|
||||||
|
Err(LlmError::RequestFailed {
|
||||||
|
provider: "nearai_chat".to_string(),
|
||||||
|
reason: "retry loop exited unexpectedly".to_string(),
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
|
|
||||||
/// Fetch available models.
|
/// Fetch available models with full metadata from the `/v1/models` endpoint.
|
||||||
pub async fn list_models(&self) -> Result<Vec<String>, LlmError> {
|
async fn fetch_models(&self) -> Result<Vec<ApiModelEntry>, LlmError> {
|
||||||
let url = self.api_url("models");
|
let url = self.api_url("models");
|
||||||
|
|
||||||
let response = self
|
let response = self
|
||||||
@@ -138,12 +203,7 @@ impl NearAiChatProvider {
|
|||||||
|
|
||||||
#[derive(Deserialize)]
|
#[derive(Deserialize)]
|
||||||
struct ModelsResponse {
|
struct ModelsResponse {
|
||||||
data: Vec<ModelEntry>,
|
data: Vec<ApiModelEntry>,
|
||||||
}
|
|
||||||
|
|
||||||
#[derive(Deserialize)]
|
|
||||||
struct ModelEntry {
|
|
||||||
id: String,
|
|
||||||
}
|
}
|
||||||
|
|
||||||
let resp: ModelsResponse =
|
let resp: ModelsResponse =
|
||||||
@@ -152,10 +212,18 @@ impl NearAiChatProvider {
|
|||||||
reason: format!("JSON parse error: {}", e),
|
reason: format!("JSON parse error: {}", e),
|
||||||
})?;
|
})?;
|
||||||
|
|
||||||
Ok(resp.data.into_iter().map(|m| m.id).collect())
|
Ok(resp.data)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/// Model entry as returned by the `/v1/models` API.
|
||||||
|
#[derive(Debug, Deserialize)]
|
||||||
|
struct ApiModelEntry {
|
||||||
|
id: String,
|
||||||
|
#[serde(default)]
|
||||||
|
context_length: Option<u32>,
|
||||||
|
}
|
||||||
|
|
||||||
#[async_trait]
|
#[async_trait]
|
||||||
impl LlmProvider for NearAiChatProvider {
|
impl LlmProvider for NearAiChatProvider {
|
||||||
async fn complete(&self, req: CompletionRequest) -> Result<CompletionResponse, LlmError> {
|
async fn complete(&self, req: CompletionRequest) -> Result<CompletionResponse, LlmError> {
|
||||||
@@ -163,7 +231,7 @@ impl LlmProvider for NearAiChatProvider {
|
|||||||
req.messages.into_iter().map(|m| m.into()).collect();
|
req.messages.into_iter().map(|m| m.into()).collect();
|
||||||
|
|
||||||
let request = ChatCompletionRequest {
|
let request = ChatCompletionRequest {
|
||||||
model: self.config.model.clone(),
|
model: self.active_model_name(),
|
||||||
messages,
|
messages,
|
||||||
temperature: req.temperature,
|
temperature: req.temperature,
|
||||||
max_tokens: req.max_tokens,
|
max_tokens: req.max_tokens,
|
||||||
@@ -197,6 +265,7 @@ impl LlmProvider for NearAiChatProvider {
|
|||||||
finish_reason,
|
finish_reason,
|
||||||
input_tokens: response.usage.prompt_tokens,
|
input_tokens: response.usage.prompt_tokens,
|
||||||
output_tokens: response.usage.completion_tokens,
|
output_tokens: response.usage.completion_tokens,
|
||||||
|
response_id: None,
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -207,6 +276,12 @@ impl LlmProvider for NearAiChatProvider {
|
|||||||
let messages: Vec<ChatCompletionMessage> =
|
let messages: Vec<ChatCompletionMessage> =
|
||||||
req.messages.into_iter().map(|m| m.into()).collect();
|
req.messages.into_iter().map(|m| m.into()).collect();
|
||||||
|
|
||||||
|
// NEAR AI cloud-api does not support multi-turn tool calling (rejects
|
||||||
|
// any request containing role:"tool" messages with HTTP 400). Rewrite
|
||||||
|
// tool-call / tool-result pairs into plain text so the conversation
|
||||||
|
// history is preserved without using unsupported message roles.
|
||||||
|
let messages = flatten_tool_messages(messages);
|
||||||
|
|
||||||
let tools: Vec<ChatCompletionTool> = req
|
let tools: Vec<ChatCompletionTool> = req
|
||||||
.tools
|
.tools
|
||||||
.into_iter()
|
.into_iter()
|
||||||
@@ -221,7 +296,7 @@ impl LlmProvider for NearAiChatProvider {
|
|||||||
.collect();
|
.collect();
|
||||||
|
|
||||||
let request = ChatCompletionRequest {
|
let request = ChatCompletionRequest {
|
||||||
model: self.config.model.clone(),
|
model: self.active_model_name(),
|
||||||
messages,
|
messages,
|
||||||
temperature: req.temperature,
|
temperature: req.temperature,
|
||||||
max_tokens: req.max_tokens,
|
max_tokens: req.max_tokens,
|
||||||
@@ -278,6 +353,7 @@ impl LlmProvider for NearAiChatProvider {
|
|||||||
finish_reason,
|
finish_reason,
|
||||||
input_tokens: response.usage.prompt_tokens,
|
input_tokens: response.usage.prompt_tokens,
|
||||||
output_tokens: response.usage.completion_tokens,
|
output_tokens: response.usage.completion_tokens,
|
||||||
|
response_id: None,
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -291,7 +367,34 @@ impl LlmProvider for NearAiChatProvider {
|
|||||||
}
|
}
|
||||||
|
|
||||||
async fn list_models(&self) -> Result<Vec<String>, LlmError> {
|
async fn list_models(&self) -> Result<Vec<String>, LlmError> {
|
||||||
NearAiChatProvider::list_models(self).await
|
let models = self.fetch_models().await?;
|
||||||
|
Ok(models.into_iter().map(|m| m.id).collect())
|
||||||
|
}
|
||||||
|
|
||||||
|
async fn model_metadata(&self) -> Result<ModelMetadata, LlmError> {
|
||||||
|
let active = self.active_model_name();
|
||||||
|
let models = self.fetch_models().await?;
|
||||||
|
let current = models.iter().find(|m| m.id == active);
|
||||||
|
Ok(ModelMetadata {
|
||||||
|
id: active,
|
||||||
|
context_length: current.and_then(|m| m.context_length),
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
|
fn active_model_name(&self) -> String {
|
||||||
|
self.active_model
|
||||||
|
.read()
|
||||||
|
.expect("active_model lock poisoned")
|
||||||
|
.clone()
|
||||||
|
}
|
||||||
|
|
||||||
|
fn set_model(&self, model: &str) -> Result<(), crate::error::LlmError> {
|
||||||
|
let mut guard = self
|
||||||
|
.active_model
|
||||||
|
.write()
|
||||||
|
.expect("active_model lock poisoned");
|
||||||
|
*guard = model.to_string();
|
||||||
|
Ok(())
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -324,6 +427,64 @@ struct ChatCompletionMessage {
|
|||||||
tool_calls: Option<Vec<ChatCompletionToolCall>>,
|
tool_calls: Option<Vec<ChatCompletionToolCall>>,
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/// Rewrite tool-call / tool-result messages into plain assistant/user text.
|
||||||
|
///
|
||||||
|
/// NEAR AI cloud-api does not support the OpenAI multi-turn tool-calling
|
||||||
|
/// protocol (`role: "tool"` messages). This function converts:
|
||||||
|
/// - Assistant messages with `tool_calls` → assistant text describing the calls
|
||||||
|
/// - Tool result messages (`role: "tool"`) → user messages with the result
|
||||||
|
///
|
||||||
|
/// Non-tool messages pass through unchanged.
|
||||||
|
fn flatten_tool_messages(messages: Vec<ChatCompletionMessage>) -> Vec<ChatCompletionMessage> {
|
||||||
|
let has_tool_msgs = messages.iter().any(|m| m.role == "tool");
|
||||||
|
if !has_tool_msgs {
|
||||||
|
return messages;
|
||||||
|
}
|
||||||
|
|
||||||
|
tracing::debug!("Flattening tool messages for NEAR AI compatibility");
|
||||||
|
|
||||||
|
messages
|
||||||
|
.into_iter()
|
||||||
|
.map(|msg| {
|
||||||
|
if let (true, Some(calls)) = (msg.role == "assistant", &msg.tool_calls) {
|
||||||
|
// Convert assistant tool_calls into descriptive text
|
||||||
|
let mut parts: Vec<String> = Vec::new();
|
||||||
|
if let Some(ref text) = msg.content
|
||||||
|
&& !text.is_empty()
|
||||||
|
{
|
||||||
|
parts.push(text.clone());
|
||||||
|
}
|
||||||
|
for tc in calls {
|
||||||
|
parts.push(format!(
|
||||||
|
"[Called tool `{}` with arguments: {}]",
|
||||||
|
tc.function.name, tc.function.arguments
|
||||||
|
));
|
||||||
|
}
|
||||||
|
ChatCompletionMessage {
|
||||||
|
role: "assistant".to_string(),
|
||||||
|
content: Some(parts.join("\n")),
|
||||||
|
tool_call_id: None,
|
||||||
|
name: None,
|
||||||
|
tool_calls: None,
|
||||||
|
}
|
||||||
|
} else if msg.role == "tool" {
|
||||||
|
// Convert tool result into a user message
|
||||||
|
let tool_name = msg.name.as_deref().unwrap_or("unknown");
|
||||||
|
let result = msg.content.as_deref().unwrap_or("");
|
||||||
|
ChatCompletionMessage {
|
||||||
|
role: "user".to_string(),
|
||||||
|
content: Some(format!("[Tool `{}` returned: {}]", tool_name, result)),
|
||||||
|
tool_call_id: None,
|
||||||
|
name: None,
|
||||||
|
tool_calls: None,
|
||||||
|
}
|
||||||
|
} else {
|
||||||
|
msg
|
||||||
|
}
|
||||||
|
})
|
||||||
|
.collect()
|
||||||
|
}
|
||||||
|
|
||||||
impl From<ChatMessage> for ChatCompletionMessage {
|
impl From<ChatMessage> for ChatCompletionMessage {
|
||||||
fn from(msg: ChatMessage) -> Self {
|
fn from(msg: ChatMessage) -> Self {
|
||||||
let role = match msg.role {
|
let role = match msg.role {
|
||||||
@@ -332,6 +493,7 @@ impl From<ChatMessage> for ChatCompletionMessage {
|
|||||||
Role::Assistant => "assistant",
|
Role::Assistant => "assistant",
|
||||||
Role::Tool => "tool",
|
Role::Tool => "tool",
|
||||||
};
|
};
|
||||||
|
|
||||||
let tool_calls = msg.tool_calls.map(|calls| {
|
let tool_calls = msg.tool_calls.map(|calls| {
|
||||||
calls
|
calls
|
||||||
.into_iter()
|
.into_iter()
|
||||||
@@ -345,9 +507,16 @@ impl From<ChatMessage> for ChatCompletionMessage {
|
|||||||
})
|
})
|
||||||
.collect()
|
.collect()
|
||||||
});
|
});
|
||||||
|
|
||||||
|
let content = if role == "assistant" && tool_calls.is_some() && msg.content.is_empty() {
|
||||||
|
None
|
||||||
|
} else {
|
||||||
|
Some(msg.content)
|
||||||
|
};
|
||||||
|
|
||||||
Self {
|
Self {
|
||||||
role: role.to_string(),
|
role: role.to_string(),
|
||||||
content: Some(msg.content),
|
content,
|
||||||
tool_call_id: msg.tool_call_id,
|
tool_call_id: msg.tool_call_id,
|
||||||
name: msg.name,
|
name: msg.name,
|
||||||
tool_calls,
|
tool_calls,
|
||||||
@@ -454,7 +623,7 @@ mod tests {
|
|||||||
},
|
},
|
||||||
];
|
];
|
||||||
|
|
||||||
let msg = ChatMessage::assistant_with_tool_calls("", tool_calls);
|
let msg = ChatMessage::assistant_with_tool_calls(None, tool_calls);
|
||||||
let chat_msg: ChatCompletionMessage = msg.into();
|
let chat_msg: ChatCompletionMessage = msg.into();
|
||||||
|
|
||||||
assert_eq!(chat_msg.role, "assistant");
|
assert_eq!(chat_msg.role, "assistant");
|
||||||
@@ -484,7 +653,7 @@ mod tests {
|
|||||||
name: "test".to_string(),
|
name: "test".to_string(),
|
||||||
arguments: serde_json::json!({"key": "value"}),
|
arguments: serde_json::json!({"key": "value"}),
|
||||||
};
|
};
|
||||||
let msg = ChatMessage::assistant_with_tool_calls("", vec![tc]);
|
let msg = ChatMessage::assistant_with_tool_calls(None, vec![tc]);
|
||||||
let chat_msg: ChatCompletionMessage = msg.into();
|
let chat_msg: ChatCompletionMessage = msg.into();
|
||||||
|
|
||||||
let calls = chat_msg.tool_calls.unwrap();
|
let calls = chat_msg.tool_calls.unwrap();
|
||||||
@@ -493,4 +662,119 @@ mod tests {
|
|||||||
serde_json::from_str(&calls[0].function.arguments).expect("valid JSON string");
|
serde_json::from_str(&calls[0].function.arguments).expect("valid JSON string");
|
||||||
assert_eq!(parsed["key"], "value");
|
assert_eq!(parsed["key"], "value");
|
||||||
}
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_flatten_no_tool_messages_passthrough() {
|
||||||
|
let messages = vec![
|
||||||
|
ChatCompletionMessage {
|
||||||
|
role: "system".to_string(),
|
||||||
|
content: Some("You are helpful.".to_string()),
|
||||||
|
tool_call_id: None,
|
||||||
|
name: None,
|
||||||
|
tool_calls: None,
|
||||||
|
},
|
||||||
|
ChatCompletionMessage {
|
||||||
|
role: "user".to_string(),
|
||||||
|
content: Some("Hello".to_string()),
|
||||||
|
tool_call_id: None,
|
||||||
|
name: None,
|
||||||
|
tool_calls: None,
|
||||||
|
},
|
||||||
|
];
|
||||||
|
let result = flatten_tool_messages(messages);
|
||||||
|
assert_eq!(result.len(), 2);
|
||||||
|
assert_eq!(result[0].role, "system");
|
||||||
|
assert_eq!(result[1].role, "user");
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_flatten_tool_call_and_result() {
|
||||||
|
let messages = vec![
|
||||||
|
ChatCompletionMessage {
|
||||||
|
role: "user".to_string(),
|
||||||
|
content: Some("test".to_string()),
|
||||||
|
tool_call_id: None,
|
||||||
|
name: None,
|
||||||
|
tool_calls: None,
|
||||||
|
},
|
||||||
|
ChatCompletionMessage {
|
||||||
|
role: "assistant".to_string(),
|
||||||
|
content: None,
|
||||||
|
tool_call_id: None,
|
||||||
|
name: None,
|
||||||
|
tool_calls: Some(vec![ChatCompletionToolCall {
|
||||||
|
id: "call_1".to_string(),
|
||||||
|
call_type: "function".to_string(),
|
||||||
|
function: ChatCompletionToolCallFunction {
|
||||||
|
name: "echo".to_string(),
|
||||||
|
arguments: r#"{"message":"hi"}"#.to_string(),
|
||||||
|
},
|
||||||
|
}]),
|
||||||
|
},
|
||||||
|
ChatCompletionMessage {
|
||||||
|
role: "tool".to_string(),
|
||||||
|
content: Some("hi".to_string()),
|
||||||
|
tool_call_id: Some("call_1".to_string()),
|
||||||
|
name: Some("echo".to_string()),
|
||||||
|
tool_calls: None,
|
||||||
|
},
|
||||||
|
];
|
||||||
|
|
||||||
|
let result = flatten_tool_messages(messages);
|
||||||
|
assert_eq!(result.len(), 3);
|
||||||
|
|
||||||
|
// Assistant tool_calls → plain assistant text
|
||||||
|
assert_eq!(result[1].role, "assistant");
|
||||||
|
assert!(result[1].tool_calls.is_none());
|
||||||
|
assert!(
|
||||||
|
result[1]
|
||||||
|
.content
|
||||||
|
.as_ref()
|
||||||
|
.unwrap()
|
||||||
|
.contains("[Called tool `echo`")
|
||||||
|
);
|
||||||
|
|
||||||
|
// Tool result → user message
|
||||||
|
assert_eq!(result[2].role, "user");
|
||||||
|
assert!(result[2].tool_call_id.is_none());
|
||||||
|
assert!(
|
||||||
|
result[2]
|
||||||
|
.content
|
||||||
|
.as_ref()
|
||||||
|
.unwrap()
|
||||||
|
.contains("[Tool `echo` returned: hi]")
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn test_flatten_preserves_assistant_text_with_tool_calls() {
|
||||||
|
let messages = vec![
|
||||||
|
ChatCompletionMessage {
|
||||||
|
role: "assistant".to_string(),
|
||||||
|
content: Some("Let me check that.".to_string()),
|
||||||
|
tool_call_id: None,
|
||||||
|
name: None,
|
||||||
|
tool_calls: Some(vec![ChatCompletionToolCall {
|
||||||
|
id: "call_1".to_string(),
|
||||||
|
call_type: "function".to_string(),
|
||||||
|
function: ChatCompletionToolCallFunction {
|
||||||
|
name: "search".to_string(),
|
||||||
|
arguments: r#"{"q":"test"}"#.to_string(),
|
||||||
|
},
|
||||||
|
}]),
|
||||||
|
},
|
||||||
|
ChatCompletionMessage {
|
||||||
|
role: "tool".to_string(),
|
||||||
|
content: Some("found it".to_string()),
|
||||||
|
tool_call_id: Some("call_1".to_string()),
|
||||||
|
name: Some("search".to_string()),
|
||||||
|
tool_calls: None,
|
||||||
|
},
|
||||||
|
];
|
||||||
|
|
||||||
|
let result = flatten_tool_messages(messages);
|
||||||
|
let text = result[0].content.as_ref().unwrap();
|
||||||
|
assert!(text.starts_with("Let me check that."));
|
||||||
|
assert!(text.contains("[Called tool `search`"));
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user